7.5
CVE-2021-39923
- EPSS 1.53%
- Veröffentlicht 19.11.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:20:34
- Erkennungen
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.53% | 0.72 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
| cve@gitlab.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-834 Excessive Iteration
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
https://lists.debian.org/debian-lts-announce/2021/12/msg00015.html
https://www.debian.org/security/2021/dsa-5019
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39923.json
https://gitlab.com/wireshark/wireshark/-/issues/17684
https://www.wireshark.org/security/wnpa-sec-2021-11.html