CVE-2020-26418
published 2020-12-11CVE-2020-26418: Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.96%
85.7th percentile
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 3.4.1-1 (bookworm) | wireshark 3.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| the_wireshark_foundation | wireshark | — | — |
| the_wireshark_foundation | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | 3.2.0 – 3.2.8 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63gq-cvv8-gc2g: Memory leak in Kafka protocol dissector in Wireshark 3
ghsa_unreviewed·2022-05-24
CVE-2020-26418 [MEDIUM] CWE-401 GHSA-63gq-cvv8-gc2g: Memory leak in Kafka protocol dissector in Wireshark 3
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
OSV
CVE-2020-26418: Memory leak in Kafka protocol dissector in Wireshark 3
osv·2020-12-11·CVSS 5.3
CVE-2020-26418 [MEDIUM] CVE-2020-26418: Memory leak in Kafka protocol dissector in Wireshark 3
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Red Hat
wireshark: Kafka dissector memory leak (wnpa-sec-2020-16)
vendor_redhat·2020-12-09·CVSS 3.1
CVE-2020-26418 [LOW] CWE-770 wireshark: Kafka dissector memory leak (wnpa-sec-2020-16)
wireshark: Kafka dissector memory leak (wnpa-sec-2020-16)
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
A flaw was discovered in the Apache Kafka protocol dissector of Wireshark while decoding packets captured in a pcap file or coming from the network. A remote attacker may abuse this flaw by sending specially crafted packets that, when processed, would potentially make Wireshark crash resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Statement: This issue does not affect the versions of `wireshark` as shipped with Red Hat Enterprise Linux 5, 6, and 7, as they did not include support for the Apache Kafka dissector.
Package: wiresha
Debian
CVE-2020-26418: wireshark - Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 al...
vendor_debian·2020·CVSS 3.1
CVE-2020-26418 [LOW] CVE-2020-26418: wireshark - Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 al...
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/16739https://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-16.htmlhttps://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/16739https://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-16.html
2020-12-11
Published