CVE-2020-26418: Medium severity wireshark vulnerability
Published Dec 11, 2020
·Updated
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected Software
6 affected components
Wireshark Wireshark>=3.2.0<=3.2.8
Wireshark Wireshark=3.4.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 11, 2020
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26418?
CVE-2020-26418 has a severity rating that indicates it can lead to denial of service due to a memory leak.
2
How do I fix CVE-2020-26418?
To fix CVE-2020-26418, update Wireshark to the latest version that is not affected by this vulnerability.
3
What versions of Wireshark are affected by CVE-2020-26418?
Wireshark versions 3.4.0 and 3.2.0 through 3.2.8 are affected by CVE-2020-26418.
4
Can CVE-2020-26418 be exploited via crafted packets?
Yes, CVE-2020-26418 can be exploited through packet injection or by using a crafted capture file.
5
Which operating systems are impacted by CVE-2020-26418?
CVE-2020-26418 impacts software running on Fedora 32, Fedora 33, Debian 9.0, and Oracle Sun ZFS Storage Appliance Kit 8.8.