Infinite loop in Wireshark - CVE-2020-26575
Published: October 6, 2020 / Updated: October 30, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the Facebook Zero Protocol (aka FBZERO) dissector in epan/dissectors/packet-fbzero.c. A remote attacker can pass specially crafted traffic to the application, consume all available system resources and cause denial of service conditions.
Affected software
Gentoo Linux
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debugsource
wireshark-debuginfo
wireshark-devel
wireshark-help
How to mitigate CVE-2020-26575
wireshark (Alpine package) - update to 3.4.0-r0
wireshark - update to 2.6.2-17
wireshark-debugsource - update to 2.6.2-17
wireshark-debuginfo - update to 2.6.2-17
wireshark-devel - update to 2.6.2-17
wireshark-help - update to 2.6.2-17
wireshark - addressed in versions 3.4.0-1.fc32, 3.4.0-1.fc33
External References
- https://www.wireshark.org/security/wnpa-sec-2020-14.html
- https://gitlab.com/wireshark/wireshark/-/commit/3ff940652962c099b73ae3233322b8697b0d10ab
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/merge_requests/467
- https://gitlab.com/wireshark/wireshark/-/merge_requests/471
- https://gitlab.com/wireshark/wireshark/-/merge_requests/472
- https://gitlab.com/wireshark/wireshark/-/merge_requests/473