Input validation error in Wireshark - CVE-2021-22191

 

Input validation error in Wireshark - CVE-2021-22191

Published: March 11, 2021


Vulnerability identifier: #VU51385
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22191
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing URLs. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Wireshark
Gentoo Linux
Arch Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
openEuler
libsbc1
libsbc1-debuginfo
sbc-debuginfo
sbc-debugsource
sbc-devel
wireshark-help
wireshark-debuginfo
wireshark-debugsource
wireshark
wireshark-devel
wireshark-ui-qt-debuginfo
wireshark-ui-qt
libwsutil12-debuginfo
libwsutil12
libwiretap11-debuginfo
libwiretap11
libwireshark14-debuginfo
libwireshark14
libvirt-debugsource
libvirt-daemon-qemu
libvirt-daemon-lxc
libvirt-daemon-hooks
libvirt-daemon-driver-storage-scsi-debuginfo
libvirt-daemon-driver-storage-scsi
libvirt-daemon-driver-storage-mpath-debuginfo
libvirt-daemon-driver-storage-mpath
libvirt-daemon-driver-storage-logical-debuginfo
libvirt-daemon-driver-storage-logical
libvirt-daemon-driver-storage-iscsi-debuginfo
libvirt-daemon-driver-storage-iscsi
libvirt-daemon-driver-nwfilter-debuginfo
libvirt-daemon-driver-storage-disk-debuginfo
libvirt-devel
libvirt-doc
libvirt-libs
libvirt-libs-debuginfo
libvirt-lock-sanlock
libvirt-lock-sanlock-debuginfo
libvirt-nss
libvirt-nss-debuginfo
libvirt-daemon-driver-libxl
libvirt-daemon-driver-libxl-debuginfo
libvirt-daemon-driver-storage-rbd
libvirt-daemon-driver-storage-rbd-debuginfo
libvirt-daemon-xen
libvirt-daemon-driver-storage-core-debuginfo
libvirt
libvirt-admin
libvirt-admin-debuginfo
libvirt-client
libvirt-client-debuginfo
libvirt-daemon
libvirt-daemon-config-network
libvirt-daemon-config-nwfilter
libvirt-daemon-debuginfo
libvirt-daemon-driver-interface
libvirt-daemon-driver-interface-debuginfo
libvirt-daemon-driver-lxc
libvirt-daemon-driver-lxc-debuginfo
libvirt-daemon-driver-network-debuginfo
libvirt-daemon-driver-storage-disk
libvirt-daemon-driver-storage-core
libvirt-daemon-driver-storage
libvirt-daemon-driver-secret-debuginfo
libvirt-daemon-driver-secret
libvirt-daemon-driver-qemu-debuginfo
libvirt-daemon-driver-qemu
libvirt-daemon-driver-nwfilter
libvirt-daemon-driver-nodedev-debuginfo
libvirt-daemon-driver-nodedev
libvirt-daemon-driver-network
libQt5Multimedia5
libqt5-qtmultimedia-private-headers-devel
libqt5-qtmultimedia-devel
libqt5-qtmultimedia-debugsource
libQt5Multimedia5-debuginfo

How to mitigate CVE-2021-22191

Install updates from vendor's website.

Wireshark - addressed in versions 3.2.12, 3.4.4
libsbc1 - update to 1.3-3.2.1
libsbc1-debuginfo - update to 1.3-3.2.1
sbc-debuginfo - update to 1.3-3.2.1
sbc-debugsource - update to 1.3-3.2.1
sbc-devel - update to 1.3-3.2.1
wireshark-help - update to 2.6.2-21
wireshark-debuginfo - update to 2.6.2-21
wireshark-debugsource - update to 2.6.2-21
wireshark - update to 2.6.2-21
wireshark-devel - update to 2.6.2-21
wireshark-devel - update to 3.4.5-3.53.1
wireshark-ui-qt-debuginfo - update to 3.4.5-3.53.1
wireshark-ui-qt - update to 3.4.5-3.53.1
wireshark-debugsource - update to 3.4.5-3.53.1
wireshark-debuginfo - update to 3.4.5-3.53.1
libwsutil12-debuginfo - update to 3.4.5-3.53.1
libwsutil12 - update to 3.4.5-3.53.1
wireshark - update to 3.4.5-3.53.1
libwiretap11-debuginfo - update to 3.4.5-3.53.1
libwiretap11 - update to 3.4.5-3.53.1
libwireshark14-debuginfo - update to 3.4.5-3.53.1
libwireshark14 - update to 3.4.5-3.53.1
libvirt-debugsource - update to 4.0.0-9.37.21
libvirt-daemon-qemu - update to 4.0.0-9.37.21
libvirt-daemon-lxc - update to 4.0.0-9.37.21
libvirt-daemon-hooks - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-disk-debuginfo - update to 4.0.0-9.37.21
libvirt-devel - update to 4.0.0-9.37.21
libvirt-doc - update to 4.0.0-9.37.21
libvirt-libs - update to 4.0.0-9.37.21
libvirt-libs-debuginfo - update to 4.0.0-9.37.21
libvirt-lock-sanlock - update to 4.0.0-9.37.21
libvirt-lock-sanlock-debuginfo - update to 4.0.0-9.37.21
libvirt-nss - update to 4.0.0-9.37.21
libvirt-nss-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-xen - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core-debuginfo - update to 4.0.0-9.37.21
libvirt - update to 4.0.0-9.37.21
libvirt-admin - update to 4.0.0-9.37.21
libvirt-admin-debuginfo - update to 4.0.0-9.37.21
libvirt-client - update to 4.0.0-9.37.21
libvirt-client-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon - update to 4.0.0-9.37.21
libvirt-daemon-config-network - update to 4.0.0-9.37.21
libvirt-daemon-config-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-network-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-disk - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev - update to 4.0.0-9.37.21
libvirt-daemon-driver-network - update to 4.0.0-9.37.21
libQt5Multimedia5 - update to 5.9.7-7.2.1
libqt5-qtmultimedia-private-headers-devel - update to 5.9.7-7.2.1
libqt5-qtmultimedia-devel - update to 5.9.7-7.2.1
libqt5-qtmultimedia-debugsource - update to 5.9.7-7.2.1
libQt5Multimedia5-debuginfo - update to 5.9.7-7.2.1

External References

Related Security Bulletins