CVE-2020-26420: Medium severity wireshark vulnerability
Published Dec 11, 2020
·Updated
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected Software
5 affected components
Wireshark Wireshark>=3.2.0<=3.2.8
Wireshark Wireshark=3.4.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 11, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26420?
CVE-2020-26420 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2020-26420?
To fix CVE-2020-26420, users should upgrade to Wireshark version 3.4.1 or higher, or 3.2.9 or higher.
3
What software versions are affected by CVE-2020-26420?
CVE-2020-26420 affects Wireshark versions 3.2.0 to 3.2.8 and version 3.4.0.
4
What is the impact of CVE-2020-26420 on Wireshark?
The impact of CVE-2020-26420 is a memory leak, which can lead to denial of service via crafted packets.
5
Can CVE-2020-26420 be exploited remotely?
Yes, CVE-2020-26420 can be exploited remotely through packet injection or crafted capture files.