First published: Fri Dec 11 2020(Updated: )
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark | >=3.2.0<=3.2.8 | |
Wireshark | =3.4.0 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 | |
Debian Linux | =9.0 | |
Oracle Storage Cloud Software Appliance | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26421 has been classified with a severity rating that allows denial of service through crafted packet injection.
To address CVE-2020-26421, upgrade Wireshark versions to 3.2.9 or later or 3.4.1 or later.
CVE-2020-26421 affects Wireshark versions from 3.2.0 to 3.2.8 and 3.4.0.
CVE-2020-26421 can be exploited by an attacker via packet injection, resulting in a denial of service.
CVE-2020-26421 can affect multiple operating systems running vulnerable versions of Wireshark.