Memory leak in Wireshark - CVE-2020-9431
Published: February 27, 2020 / Updated: April 9, 2020
Vulnerability identifier: #VU25642
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9431
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in LTE RRC dissector within "epan/dissectors/packet-lte-rrc.c". A remote attacker can pass specially crafted data to the application and perform denial of service attack.
Affected software
Wireshark
Gentoo Linux
Oracle Solaris
Opensuse
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help
Gentoo Linux
Oracle Solaris
Opensuse
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help
How to mitigate CVE-2020-9431
Install updates from vendor's website.
Wireshark - addressed in versions 2.6.15, 3.0.9, 3.2.2
wireshark (Alpine package) - update to 3.0.9-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18
wireshark - addressed in versions 3.2.2-1.fc30, 3.2.2-1.fc31, 3.2.2-1.fc32, 3.2.3-1.fc30, 3.2.3-1.fc31, 3.2.3-1.fc32
wireshark (Alpine package) - update to 3.0.9-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18
wireshark - addressed in versions 3.2.2-1.fc30, 3.2.2-1.fc31, 3.2.2-1.fc32, 3.2.3-1.fc30, 3.2.3-1.fc31, 3.2.3-1.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in Wireshark
- Oracle Solaris update for third party packages
- Gentoo update for Wireshark
- OpenSUSE Linux update for wireshark
- Memory leak in wireshark (Alpine package)
- openEuler update for wireshark
- Fedora 31 update for wireshark
- Fedora 30 update for wireshark
- Fedora 32 update for wireshark
- Fedora 31 update for wireshark
- Fedora 32 update for wireshark
- Fedora 30 update for wireshark