Memory leak in Wireshark - CVE-2020-26419

 

Memory leak in Wireshark - CVE-2020-26419

Published: December 16, 2020 / Updated: December 19, 2020


Vulnerability identifier: #VU49034
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-26419
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. A remote attacker can perform a denial of service attack.


Affected software

Wireshark
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
Fedora
wireshark (Alpine package)
libsbc1
libsbc1-debuginfo
sbc-devel
sbc-debugsource
sbc-debuginfo
wireshark
wireshark-debuginfo
wireshark-ui-qt-debuginfo
wireshark-ui-qt
wireshark-devel
wireshark-debugsource
libwsutil12
libwiretap11-debuginfo
libwsutil12-debuginfo
libwiretap11
libwireshark14-debuginfo
libwireshark14
libvirt-daemon-qemu
libvirt-daemon-lxc
libvirt-daemon-hooks
libvirt-daemon-driver-storage-scsi-debuginfo
libvirt-daemon-driver-storage-scsi
libvirt-daemon-driver-nodedev-debuginfo
libvirt-daemon-driver-storage-mpath-debuginfo
libvirt-daemon-driver-storage-mpath
libvirt-daemon-driver-storage-logical-debuginfo
libvirt-daemon-driver-storage-logical
libvirt-daemon-driver-storage-iscsi-debuginfo
libvirt-daemon-driver-storage-iscsi
libvirt-daemon-driver-storage-disk-debuginfo
libvirt-daemon-driver-storage-disk
libvirt-debugsource
libvirt-devel
libvirt-doc
libvirt-libs
libvirt-libs-debuginfo
libvirt-lock-sanlock
libvirt-lock-sanlock-debuginfo
libvirt-nss
libvirt-nss-debuginfo
libvirt-daemon-driver-libxl
libvirt-daemon-driver-libxl-debuginfo
libvirt-daemon-driver-storage-rbd
libvirt-daemon-driver-storage-rbd-debuginfo
libvirt-daemon-xen
libvirt-daemon-driver-storage-core
libvirt
libvirt-admin
libvirt-admin-debuginfo
libvirt-client
libvirt-client-debuginfo
libvirt-daemon
libvirt-daemon-config-network
libvirt-daemon-config-nwfilter
libvirt-daemon-debuginfo
libvirt-daemon-driver-interface
libvirt-daemon-driver-interface-debuginfo
libvirt-daemon-driver-lxc
libvirt-daemon-driver-network
libvirt-daemon-driver-storage-core-debuginfo
libvirt-daemon-driver-storage
libvirt-daemon-driver-secret-debuginfo
libvirt-daemon-driver-secret
libvirt-daemon-driver-qemu-debuginfo
libvirt-daemon-driver-qemu
libvirt-daemon-driver-nwfilter-debuginfo
libvirt-daemon-driver-nwfilter
libvirt-daemon-driver-nodedev
libvirt-daemon-driver-network-debuginfo
libvirt-daemon-driver-lxc-debuginfo
libqt5-qtmultimedia-private-headers-devel
libqt5-qtmultimedia-devel
libqt5-qtmultimedia-debugsource
libQt5Multimedia5-debuginfo
libQt5Multimedia5

How to mitigate CVE-2020-26419

Install update from vendor's website.

Wireshark - update to 3.4.1
wireshark (Alpine package) - update to 3.4.1-r0
libsbc1 - update to 1.3-3.2.1
libsbc1-debuginfo - update to 1.3-3.2.1
sbc-devel - update to 1.3-3.2.1
sbc-debugsource - update to 1.3-3.2.1
sbc-debuginfo - update to 1.3-3.2.1
wireshark - addressed in versions 3.4.2-1.fc32, 3.4.2-1.fc33
wireshark-debuginfo - update to 3.4.5-3.53.1
wireshark-ui-qt-debuginfo - update to 3.4.5-3.53.1
wireshark-ui-qt - update to 3.4.5-3.53.1
wireshark-devel - update to 3.4.5-3.53.1
wireshark-debugsource - update to 3.4.5-3.53.1
wireshark - update to 3.4.5-3.53.1
libwsutil12 - update to 3.4.5-3.53.1
libwiretap11-debuginfo - update to 3.4.5-3.53.1
libwsutil12-debuginfo - update to 3.4.5-3.53.1
libwiretap11 - update to 3.4.5-3.53.1
libwireshark14-debuginfo - update to 3.4.5-3.53.1
libwireshark14 - update to 3.4.5-3.53.1
libvirt-daemon-qemu - update to 4.0.0-9.37.21
libvirt-daemon-lxc - update to 4.0.0-9.37.21
libvirt-daemon-hooks - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-scsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-mpath - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-logical - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-iscsi - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-disk-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-disk - update to 4.0.0-9.37.21
libvirt-debugsource - update to 4.0.0-9.37.21
libvirt-devel - update to 4.0.0-9.37.21
libvirt-doc - update to 4.0.0-9.37.21
libvirt-libs - update to 4.0.0-9.37.21
libvirt-libs-debuginfo - update to 4.0.0-9.37.21
libvirt-lock-sanlock - update to 4.0.0-9.37.21
libvirt-lock-sanlock-debuginfo - update to 4.0.0-9.37.21
libvirt-nss - update to 4.0.0-9.37.21
libvirt-nss-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl - update to 4.0.0-9.37.21
libvirt-daemon-driver-libxl-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-rbd-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-xen - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core - update to 4.0.0-9.37.21
libvirt - update to 4.0.0-9.37.21
libvirt-admin - update to 4.0.0-9.37.21
libvirt-admin-debuginfo - update to 4.0.0-9.37.21
libvirt-client - update to 4.0.0-9.37.21
libvirt-client-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon - update to 4.0.0-9.37.21
libvirt-daemon-config-network - update to 4.0.0-9.37.21
libvirt-daemon-config-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface - update to 4.0.0-9.37.21
libvirt-daemon-driver-interface-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc - update to 4.0.0-9.37.21
libvirt-daemon-driver-network - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage-core-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-storage - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-secret - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-qemu - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-nwfilter - update to 4.0.0-9.37.21
libvirt-daemon-driver-nodedev - update to 4.0.0-9.37.21
libvirt-daemon-driver-network-debuginfo - update to 4.0.0-9.37.21
libvirt-daemon-driver-lxc-debuginfo - update to 4.0.0-9.37.21
libqt5-qtmultimedia-private-headers-devel - update to 5.9.7-7.2.1
libqt5-qtmultimedia-devel - update to 5.9.7-7.2.1
libqt5-qtmultimedia-debugsource - update to 5.9.7-7.2.1
libQt5Multimedia5-debuginfo - update to 5.9.7-7.2.1
libQt5Multimedia5 - update to 5.9.7-7.2.1

External References

Related Security Bulletins