HIGH 7.5 Microsoft
CVE-2021-39922
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Microsoft Security Update 2021-Nov: Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Affected Products
- cbl2 wireshark 3.4.14-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-39922
- https://nvd.nist.gov/vuln/detail/CVE-2021-39922
This high severity vulnerability with a CVSS score of 7.5 was published on 2021-11-09 via Microsoft. EPSS score: 5.2% (top 8% of all CVEs by exploitation probability). Affected: cbl2 wireshark 3.4.14-1 on CBL Mariner 2.0.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.