CVE-2021-39928

NameCVE-2021-39928
DescriptionNULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wireshark (PTS)stretch2.6.7-1~deb9u1vulnerable
stretch (security)2.6.20-0+deb9u1vulnerable
buster2.6.20-0+deb10u1vulnerable
bullseye3.4.4-1vulnerable
bookworm, sid3.6.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wiresharksource(unstable)3.6.0-1

Notes

https://gitlab.com/wireshark/wireshark/-/issues/17704
https://www.wireshark.org/security/wnpa-sec-2021-13.html

Search for package or bug name: Reporting problems