Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cl0Und Syclover Security Team

#39078of 53,635
7.1Total CVSS
Vulnerabilities · 1
PT-2020-5442
7.1
2020-07-03
Wireshark · Wireshark · CVE-2020-17498
**Name of the Vulnerable Software and Affected Versions** Wireshark versions 3.2.0 through 3.2.5 **Description** The issue is related to the Kafka protocol dissector component in Wireshark, which could crash due to a double free error during LZ4 decompression. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by modifying the epan/dissectors/packet-kafka.c file to avoid the double free error. **Recommendations** For Wireshark versions 3.2.0 through 3.2.5, update the software to a version where the issue has been fixed, specifically by applying the changes made to the epan/dissectors/packet-kafka.c file to avoid the double free error during LZ4 decompression. As a temporary workaround, consider disabling the Kafka protocol dissector until a patch is available.