Resource exhaustion in Wireshark - CVE-2020-13164
Published: May 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in NFS dissector. A remote attacker can inject a malformed packet onto the wire or trick a victim to read a malformed packet trace file and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Ubuntu
Opensuse
openEuler
Fedora
wireshark (Alpine package)
tshark (Ubuntu package)
wireshark (Ubuntu package)
wireshark-qt (Ubuntu package)
wireshark-common (Ubuntu package)
wireshark-gtk (Ubuntu package)
libwireshark13 (Ubuntu package)
libwireshark11 (Ubuntu package)
wireshark
wireshark-debuginfo
wireshark-debugsource
wireshark-devel
wireshark-help
How to mitigate CVE-2020-13164
wireshark (Alpine package) - update to 3.0.11-r0
tshark (Ubuntu package) - update to Ubuntu Pro
wireshark (Ubuntu package) - update to Ubuntu Pro
wireshark-qt (Ubuntu package) - update to Ubuntu Pro
wireshark-common (Ubuntu package) - update to Ubuntu Pro
wireshark-gtk (Ubuntu package) - update to Ubuntu Pro
libwireshark13 (Ubuntu package) - update to Ubuntu Pro
libwireshark11 (Ubuntu package) - update to Ubuntu Pro
wireshark - update to 2.6.2-9
wireshark-debuginfo - update to 2.6.2-9
wireshark-debugsource - update to 2.6.2-9
wireshark-devel - update to 2.6.2-9
wireshark-help - update to 2.6.2-9
wireshark - addressed in versions 3.2.4-1.fc31, 3.2.4-1.fc32
External References
Related Security Bulletins
- Denial of service in Wireshark
- Gentoo update for Wireshark
- OpenSUSE Linux update for wireshark
- OpenSUSE Linux update for wireshark
- Resource exhaustion in wireshark (Alpine package)
- Ubuntu update for wireshark
- openEuler 20.03 LTS update for wireshark-2.6.2-7
- Fedora 31 update for wireshark
- Fedora 32 update for wireshark