CVE-2020-7045
published 2020-01-16CVE-2020-7045: In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
PriorityP423medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
1.46%
70.5th percentile
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wireshark | < wireshark 3.2.0-1 (bookworm) | wireshark 3.2.0-1 (bookworm) |
| wireshark | wireshark | >= 0 < 3.2.0-1 | 3.2.0-1 |
| wireshark | wireshark | >= 0 < 3.2.0-1 | 3.2.0-1 |
| wireshark | wireshark | >= 0 < 3.2.0-1 | 3.2.0-1 |
| wireshark | wireshark | >= 0 < 3.2.0-1 | 3.2.0-1 |
| wireshark | wireshark | >= 3.0.0 < 3.0.8 | 3.0.8 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hx2c-xvp4-cgw4: In Wireshark 3
ghsa_unreviewed·2022-05-24
CVE-2020-7045 [MEDIUM] CWE-74 GHSA-hx2c-xvp4-cgw4: In Wireshark 3
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
OSV
CVE-2020-7045: In Wireshark 3
osv·2020-01-16·CVSS 6.5
CVE-2020-7045 [MEDIUM] CVE-2020-7045: In Wireshark 3
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
Red Hat
wireshark: invalid memory access in BT ATT dissector
vendor_redhat·2020-01-15·CVSS 6.5
CVE-2020-7045 [MEDIUM] CWE-20 wireshark: invalid memory access in BT ATT dissector
wireshark: invalid memory access in BT ATT dissector
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
An invalid memory access vulnerability was discovered in Wireshark when processing malformed Bluetooth packets. An attacker could use this flaw to send malicious Bluetooth packets that can crash Wireshark, or trick a user into running the tool on a malformed packet trace file.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
Package: wireshark (Red Hat Enterprise Linux 5) - Out of support scope
Package: wireshark (Red Hat Enterprise Linux 6) - Out of support scope
Package: wireshark (Red Hat
Debian
CVE-2020-7045: wireshark - In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addr...
vendor_debian·2020·CVSS 6.5
CVE-2020-7045 [MEDIUM] CVE-2020-7045: wireshark - In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addr...
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
Scope: local
bookworm: resolved (fixed in 3.2.0-1)
bullseye: resolved (fixed in 3.2.0-1)
forky: resolved (fixed in 3.2.0-1)
sid: resolved (fixed in 3.2.0-1)
trixie: resolved (fixed in 3.2.0-1)
No detection rules found.
No public exploits indexed.
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16258https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=01f261de41f4dd3233ef578e5c0ffb9c25c7d14dhttps://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-02.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16258https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=01f261de41f4dd3233ef578e5c0ffb9c25c7d14dhttps://lists.debian.org/debian-lts-announce/2021/02/msg00008.htmlhttps://www.wireshark.org/security/wnpa-sec-2020-02.html
2020-01-16
Published