PT-2020-5747 · Wireshark+1 · Wireshark+1
Published
2020-01-15
·
Updated
2024-06-15
·
CVE-2020-7044
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Wireshark versions 3.2.x through 3.2.0
Description:
The issue is related to the incorrect neutralization of special elements in the output of the WASSP traffic analyzer, which could allow a remote attacker to cause a denial of service. The problem is associated with off-by-one errors in the WASSP dissector.
Recommendations:
For Wireshark versions 3.2.x through 3.2.0, update to version 3.2.1 or later to resolve the issue by addressing off-by-one errors in the epan/dissectors/packet-wassp.c file.
Exploit
Fix
Out of bounds Read
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Wireshark