#VU49036 Out-of-bounds read in Wireshark - CVE-2020-26421

 

#VU49036 Out-of-bounds read in Wireshark - CVE-2020-26421

Published: December 16, 2020 / Updated: December 19, 2020


Vulnerability identifier: #VU49036
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-26421
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Wireshark
Software vendor:
Wireshark.org

Description

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.


Remediation

Install update from vendor's website.

External links