CVE-2020-26420
published 2020-12-11CVE-2020-26420: Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
2.61%
83.7th percentile
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 3.4.1-1 (bookworm) | wireshark 3.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| the_wireshark_foundation | wireshark | — | — |
| the_wireshark_foundation | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | >= 0 < 3.4.1-1 | 3.4.1-1 |
| wireshark | wireshark | 3.2.0 – 3.2.8 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rvp4-jqj8-p5fq: Memory leak in RTPS protocol dissector in Wireshark 3
ghsa_unreviewed·2022-05-24
CVE-2020-26420 [MEDIUM] CWE-401 GHSA-rvp4-jqj8-p5fq: Memory leak in RTPS protocol dissector in Wireshark 3
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
OSV
CVE-2020-26420: Memory leak in RTPS protocol dissector in Wireshark 3
osv·2020-12-11·CVSS 5.3
CVE-2020-26420 [MEDIUM] CVE-2020-26420: Memory leak in RTPS protocol dissector in Wireshark 3
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Red Hat
wireshark: RTPS dissector memory leak (wnpa-sec-2020-18)
vendor_redhat·2020-12-09·CVSS 3.1
CVE-2020-26420 [LOW] CWE-401 wireshark: RTPS dissector memory leak (wnpa-sec-2020-18)
wireshark: RTPS dissector memory leak (wnpa-sec-2020-18)
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
A memory leak was discovered in the RTPS protocol dissector of Wireshark while decoding packets captured in a pcap file or coming from the network. A remote attacker may abuse this flaw by sending specially crafted packets that, when processed, would make Wireshark consume excessive CPU resources resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Statement: This issue does not affect the versions of `wireshark` as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8, as they did not include the vulnerable code which was introduced in
Debian
CVE-2020-26420: wireshark - Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 all...
vendor_debian·2020·CVSS 3.1
CVE-2020-26420 [LOW] CVE-2020-26420: wireshark - Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 all...
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26420.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/16994https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-18.htmlhttps://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26420.jsonhttps://gitlab.com/wireshark/wireshark/-/issues/16994https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/https://security.gentoo.org/glsa/202101-12https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-18.html
2020-12-11
Published