PT-2020-6575 · Wireshark+5 · Wireshark+5

Xfwang

·

Published

2020-05-19

·

Updated

2024-06-15

·

CVE-2020-13164

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wireshark versions 2.6.0 through 2.6.16 Wireshark versions 3.0.0 through 3.0.10 Wireshark versions 3.2.0 through 3.2.3
Description The issue is related to uncontrolled recursion in the NFS dissector, which could allow a remote attacker to cause a denial of service. The problem occurs due to excessive recursion, such as when encountering a cycle in the directory graph on a filesystem. This can lead to a crash of the NFS dissector.
Recommendations For Wireshark versions 2.6.0 through 2.6.16, update the epan/dissectors/packet-nfs.c file to prevent excessive recursion. For Wireshark versions 3.0.0 through 3.0.10, update the epan/dissectors/packet-nfs.c file to prevent excessive recursion. For Wireshark versions 3.2.0 through 3.2.3, update the epan/dissectors/packet-nfs.c file to prevent excessive recursion. As a temporary workaround, consider disabling the NFS dissector until a patch is available.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2005
ALT-PU-2020-2029
BDU:2022-00277
CVE-2020-13164
DLA-2547-1
OPENSUSE-SU-2020:1188-1
OPENSUSE-SU-2020:1199-1
OPENSUSE-SU-2020_1188-1
OPENSUSE-SU-2020_1199-1
OPENSUSE-SU-2024:11513-1
SUSE-SU-2020:2144-1
USN-6262-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Suse
Ubuntu
Wireshark