PT-2020-5495 · Wireshark+3 · Wireshark+3
Published
2020-10-06
·
Updated
2024-06-15
·
CVE-2020-26575
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 3.2.7 and earlier
Description
The issue is related to the Facebook Zero Protocol (FBZERO) dissector in Wireshark, which could enter an infinite loop. This could allow a remote attacker to cause a denial of service. The problem was addressed by correcting the implementation of offset advancement in the epan/dissectors/packet-fbzero.c file.
Recommendations
For Wireshark versions 3.2.7 and earlier, update to a version where the issue has been fixed, which involves correcting the implementation of offset advancement in the epan/dissectors/packet-fbzero.c file. As a temporary workaround, consider disabling the FBZERO dissector function until a patch is available.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Suse
Wireshark