Resource exhaustion in Wireshark - CVE-2020-28030
Published: October 30, 2020 / Updated: November 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing data within GQUIC dissector in Wireshark. A remote attacker can pass specially crafted data to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Arch Linux
openEuler
Fedora
wireshark (Alpine package)
wireshark
wireshark-debuginfo
wireshark-help
wireshark-debugsource
wireshark-devel
How to mitigate CVE-2020-28030
wireshark (Alpine package) - update to 3.4.0-r0
wireshark - update to 2.6.2-15
wireshark-debuginfo - update to 2.6.2-15
wireshark-help - update to 2.6.2-15
wireshark-debugsource - update to 2.6.2-15
wireshark-devel - update to 2.6.2-15
wireshark - addressed in versions 3.4.0-1.fc32, 3.4.0-1.fc33