* CVE-2021-22173 (wnpa-sec-2021-01) Description The USB HID dissector could leak memory. Impact It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. * CVE-2021-22174 (wnpa-sec-2021-01) Description The USB HID dissector could crash. Impact It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
arm done
x86 done
amd64 done
ppc64 done
arm64 done all arches done
Cleanup: https://github.com/gentoo/gentoo/commit/ccb5fcb72b01151e5ded89f44107d6cc964330a3
Unable to check for sanity: > no match for package: net-analyzer/wireshark-3.4.3
This issue was resolved and addressed in GLSA 202107-21 at https://security.gentoo.org/glsa/202107-21 by GLSA coordinator Sam James (sam_c).