CVE-2020-17498: Double Free
Published Aug 13, 2020
·Updated
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
Affected Software
9 affected componentsFixes available
ubuntu/wireshark<3.2.3-1ubuntu0.1~
3.2.3-1ubuntu0.1~
ubuntu/wireshark<3.2.6-1
3.2.6-1
debian/wireshark
2.6.20-0+deb10u42.6.20-0+deb10u83.4.10-0+deb11u14.0.11-1~deb12u14.2.2-14.2.2-1.1
Wireshark Wireshark>=3.2.0<3.2.6
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
openSUSE Leap=15.2
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Patch Available
Event History
Aug 13, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:44 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Wireshark vulnerability?
The vulnerability ID for this Wireshark vulnerability is CVE-2020-17498.
2
What is the severity of CVE-2020-17498?
The severity of CVE-2020-17498 is medium (6.5).
3
How can the Kafka protocol dissector crash in Wireshark?
The Kafka protocol dissector in Wireshark can crash due to a double free during LZ4 decompression.
4
Which versions of Wireshark are affected by CVE-2020-17498?
Wireshark versions 3.2.0 to 3.2.5 are affected by CVE-2020-17498.
5
How can I fix CVE-2020-17498 in Wireshark?
To fix CVE-2020-17498 in Wireshark, upgrade to version 3.2.6 or later.