Double Free in Wireshark - CVE-2020-17498

 

Double Free in Wireshark - CVE-2020-17498

Published: August 20, 2020


Vulnerability identifier: #VU45824
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17498
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in Kafka dissector. A remote attacker can pass specially crafted data to the application, trigger double free error and crash the application.


Affected software

Wireshark
Gentoo Linux
Ubuntu
Opensuse
Fedora
wireshark (Alpine package)
tshark (Ubuntu package)
wireshark (Ubuntu package)
wireshark-qt (Ubuntu package)
wireshark-common (Ubuntu package)
wireshark-gtk (Ubuntu package)
libwireshark13 (Ubuntu package)
libwireshark11 (Ubuntu package)
wireshark

How to mitigate CVE-2020-17498

Install updates from vendor's website.

Wireshark - update to 3.2.6
wireshark (Alpine package) - update to 3.2.6-r0
tshark (Ubuntu package) - update to Ubuntu Pro
wireshark (Ubuntu package) - update to Ubuntu Pro
wireshark-qt (Ubuntu package) - update to Ubuntu Pro
wireshark-common (Ubuntu package) - update to Ubuntu Pro
wireshark-gtk (Ubuntu package) - update to Ubuntu Pro
libwireshark13 (Ubuntu package) - update to Ubuntu Pro
libwireshark11 (Ubuntu package) - update to Ubuntu Pro
wireshark - addressed in versions 3.2.6-1.fc31, 3.2.6-1.fc32

External References

Related Security Bulletins