CVE-2020-26419
published 2020-12-11CVE-2020-26419: Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.78%
84.8th percentile
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.1-1 (bookworm) | wireshark 3.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| the_wireshark_foundation | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: multiple dissector memory leaks (wnpa-sec-2020-19)
vendor_redhat·2020-12-09·CVSS 3.1
CVE-2020-26419 [LOW] CWE-401 wireshark: multiple dissector memory leaks (wnpa-sec-2020-19)
wireshark: multiple dissector memory leaks (wnpa-sec-2020-19)
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
A memory leak was discovered in Wireshark while decoding packets captured in a pcap file or coming from the network. Multiple packet dissectors are potentially affected by this issue. A remote attacker may abuse this flaw by sending specially crafted packets that, when processed, would make Wireshark consume excessive CPU resources resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Statement: This issue does not affect the versions of `wireshark` as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8, as the vulnerable code was introduced in a newe
Debian
CVE-2020-26419: wireshark - Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service...
vendor_debian·2020·CVSS 3.1
CVE-2020-26419 [LOW] CVE-2020-26419: wireshark - Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service...
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
GHSA
GHSA-mhq7-m27c-9qjm: Memory leak in the dissection engine in Wireshark 3
ghsa_unreviewed·2022-05-24
CVE-2020-26419 [MEDIUM] CWE-401 GHSA-mhq7-m27c-9qjm: Memory leak in the dissection engine in Wireshark 3
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
OSV
CVE-2020-26419: Memory leak in the dissection engine in Wireshark 3
osv·2020-12-11·CVSS 5.3
CVE-2020-26419 [MEDIUM] CVE-2020-26419: Memory leak in the dissection engine in Wireshark 3
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26419.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/17032https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-19.htmlhttps://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26419.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/17032https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-19.html
2020-12-11
Published