Severity
7.5HIGHNVD
EPSS
1.1%
top 22.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 24

Description

In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/wireshark< wireshark 3.2.8-0.1 (bookworm)
Debianwireshark/wireshark< 3.2.8-0.1+3
NVDwireshark/wireshark3.2.03.2.7

Also affects: Debian Linux 9.0, Fedora 32, 33

Patches

🔴Vulnerability Details

2
GHSA
GHSA-983p-wv66-ffx7: In Wireshark 32022-05-24
OSV
CVE-2020-28030: In Wireshark 32020-11-02

📋Vendor Advisories

2
Red Hat
wireshark: malformed packet on wire could make GQUIC protocol dissector loop2020-10-30
Debian
CVE-2020-28030: wireshark - In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed...2020

💬Community

2
Bugzilla
CVE-2020-28030 wireshark: malformed packet on wire could make GQUIC protocol dissector loop2020-10-30
Bugzilla
CVE-2020-28030 wireshark: malformed packet on wire could make GQUIC protocol dissector loop [fedora-all]2020-10-30