CVE-2020-26421: Medium severity wireshark vulnerability
Published Dec 11, 2020
·Updated
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected Software
6 affected components
Wireshark Wireshark>=3.2.0<=3.2.8
Wireshark Wireshark=3.4.0
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 11, 2020
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26421?
CVE-2020-26421 has been classified with a severity rating that allows denial of service through crafted packet injection.
2
How do I fix CVE-2020-26421?
To address CVE-2020-26421, upgrade Wireshark versions to 3.2.9 or later or 3.4.1 or later.
3
Which versions of Wireshark are affected by CVE-2020-26421?
CVE-2020-26421 affects Wireshark versions from 3.2.0 to 3.2.8 and 3.4.0.
4
Can CVE-2020-26421 lead to remote exploitation?
CVE-2020-26421 can be exploited by an attacker via packet injection, resulting in a denial of service.
5
Is CVE-2020-26421 specific to certain operating systems?
CVE-2020-26421 can affect multiple operating systems running vulnerable versions of Wireshark.