PT-2019-5761 · Wireshark+5 · Wireshark+5

Publicado

2019-09-01

·

Atualizado

2024-06-15

·

CVE-2020-15466

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.2.0 through 3.2.4
Description The issue is related to the GVCP dissector in Wireshark, which could enter an infinite loop. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by ensuring that an offset increases in all situations in the epan/dissectors/packet-gvcp.c file.
Recommendations For Wireshark versions 3.2.0 through 3.2.4, update to a version where the issue has been addressed, specifically by applying the fix in epan/dissectors/packet-gvcp.c that ensures the offset increases in all situations.

Correção

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-2302
ALT-PU-2020-2666
BDU:2021-01457
CVE-2020-15466
DLA-2547-1
OPENSUSE-SU-2020:1188-1
OPENSUSE-SU-2020:1199-1
OPENSUSE-SU-2020_1188-1
OPENSUSE-SU-2020_1199-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2020:2144-1
USN-6262-1

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wireshark