CVE-2020-17498Double Free in Wireshark

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 54.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateJul 31

Description

In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

NVDwireshark/wireshark3.2.03.2.6
Debianwireshark/wireshark< 3.2.6-1+3
NVDopensuse/leap15.1, 15.2+1

Also affects: Fedora 31, 32

Patches

🔴Vulnerability Details

4
OSV
wireshark vulnerabilities2023-07-31
GHSA
GHSA-948p-p2c6-64q4: In Wireshark 32022-05-24
CVEList
CVE-2020-17498: In Wireshark 32020-08-13
OSV
CVE-2020-17498: In Wireshark 32020-08-13

📋Vendor Advisories

3
Ubuntu
Wireshark vulnerabilities2023-07-31
Red Hat
wireshark: Kafka protocol dissector could crash (wnpa-sec-2020-10)2020-08-12
Debian
CVE-2020-17498: wireshark - In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was ...2020

💬Community

2
Bugzilla
CVE-2020-17498 wireshark: Kafka protocol dissector could crash (wnpa-sec-2020-10) [fedora-all]2020-08-14
Bugzilla
CVE-2020-17498 wireshark: Kafka protocol dissector could crash (wnpa-sec-2020-10)2020-08-14
CVE-2020-17498 — Double Free in Wireshark | cvebase