CVE-2020-26419: Medium severity wireshark vulnerability
Published Dec 11, 2020
·Updated
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
Affected Software
4 affected components
Wireshark Wireshark=3.4.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 11, 2020
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26419?
The severity of CVE-2020-26419 is classified as medium due to its potential for denial of service.
2
How do I fix CVE-2020-26419?
To fix CVE-2020-26419, upgrade to a later version of Wireshark that addresses this memory leak vulnerability.
3
What systems are affected by CVE-2020-26419?
CVE-2020-26419 affects Wireshark version 3.4.0 and specific versions of Fedora and Oracle ZFS Storage Appliance Kit.
4
What can be exploited in CVE-2020-26419?
CVE-2020-26419 can be exploited through packet injection or crafted capture files to cause a denial of service.
5
When was CVE-2020-26419 disclosed?
CVE-2020-26419 was disclosed in November 2020, affecting users of Wireshark 3.4.0.