PT-2020-5495 · Wireshark+3 · Wireshark+3

Published

2020-10-06

·

Updated

2024-06-15

·

CVE-2020-26575

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Wireshark versions 3.2.7 and earlier
Description The issue is related to the Facebook Zero Protocol (FBZERO) dissector in Wireshark, which could enter an infinite loop. This could allow a remote attacker to cause a denial of service. The problem was addressed by correcting the implementation of offset advancement in the epan/dissectors/packet-fbzero.c file.
Recommendations For Wireshark versions 3.2.7 and earlier, update to a version where the issue has been fixed, which involves correcting the implementation of offset advancement in the epan/dissectors/packet-fbzero.c file. As a temporary workaround, consider disabling the FBZERO dissector function until a patch is available.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3204
ALT-PU-2020-3222
ALT-PU-2022-1368
BDU:2021-00876
CVE-2020-26575
DLA-2547-1
OESA-2021-1076
OPENSUSE-SU-2020:2076-1
OPENSUSE-SU-2020:2107-1
OPENSUSE-SU-2020_2076-1
OPENSUSE-SU-2020_2107-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2020:3376-1
SUSE-SU-2020_3376-1

Affected Products

Alt Linux
Astra Linux
Suse
Wireshark