PT-2019-5761 · Wireshark+5 · Wireshark+5
Published
2019-09-01
·
Updated
2024-06-15
·
CVE-2020-15466
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 3.2.0 through 3.2.4
Description
The issue is related to the GVCP dissector in Wireshark, which could enter an infinite loop. This could potentially allow a remote attacker to cause a denial of service. The problem was addressed by ensuring that an offset increases in all situations in the epan/dissectors/packet-gvcp.c file.
Recommendations
For Wireshark versions 3.2.0 through 3.2.4, update to a version where the issue has been addressed, specifically by applying the fix in epan/dissectors/packet-gvcp.c that ensures the offset increases in all situations.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wireshark