Vulnerability CVE-2022-0582: Information

Description

Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Feb. 15, 2022
Modified: Nov. 7, 2023
Error type identifier: CWE-476

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
wiresharksisyphus3.6.2-alt14.2.5-alt1ALT-PU-2022-1349-1295749Fixed
wiresharksisyphus_e2k3.6.2-alt14.2.5-alt1ALT-PU-2022-4111-1-Fixed
wiresharkp103.6.2-alt14.0.11-alt1ALT-PU-2022-1391-1295750Fixed
wiresharkp10_e2k3.6.2-alt14.0.11-alt1ALT-PU-2022-4188-1-Fixed
wiresharkp93.6.2-alt14.0.8-alt1ALT-PU-2022-1599-1295752Fixed
wiresharkp9_e2k3.6.2-alt14.0.8-alt1ALT-PU-2022-4728-1-Fixed
wiresharkc10f13.6.2-alt14.0.11-alt1ALT-PU-2022-1391-1295750Fixed
wiresharkc9f23.6.2-alt14.0.11-alt1ALT-PU-2022-1368-1295751Fixed
wiresharkp113.6.2-alt14.2.5-alt1ALT-PU-2022-1349-1295749Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:wireshark:wireshark:3.6.0:*:*:*:*:*:*:*

      cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
      Start including
      3.4.0
      End excliding
      3.4.12

      cpe:2.3:a:wireshark:wireshark:3.6.1:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*