CVE-2021-22191

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
15/03/2021
Last modified:
27/05/2022

Description

Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* 3.2.0 (including) 3.2.11 (including)
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* 3.4.0 (including) 3.4.3 (including)
cpe:2.3:o:oracle:zfs_storage_appliance:8.8:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*