Memory leak in Wireshark - CVE-2020-9431

 

Memory leak in Wireshark - CVE-2020-9431

Published: February 27, 2020 / Updated: April 9, 2020


Vulnerability identifier: #VU25642
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9431
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in LTE RRC dissector within "epan/dissectors/packet-lte-rrc.c". A remote attacker can pass specially crafted data to the application and perform denial of service attack.


Affected software

Wireshark
Gentoo Linux
Oracle Solaris
Opensuse
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-devel
wireshark-debuginfo
wireshark-help

How to mitigate CVE-2020-9431

Install updates from vendor's website.

Wireshark - addressed in versions 2.6.15, 3.0.9, 3.2.2
wireshark (Alpine package) - update to 3.0.9-r0
wireshark - update to 2.6.2-18
wireshark-debugsource - update to 2.6.2-18
wireshark-devel - update to 2.6.2-18
wireshark-debuginfo - update to 2.6.2-18
wireshark-help - update to 2.6.2-18
wireshark - addressed in versions 3.2.2-1.fc30, 3.2.2-1.fc31, 3.2.2-1.fc32, 3.2.3-1.fc30, 3.2.3-1.fc31, 3.2.3-1.fc32

External References

Related Security Bulletins