CVE-2020-26422: Buffer Overflow
Published Dec 21, 2020
·Updated
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
Affected Software
3 affected components
Wireshark Wireshark=3.4.0
Wireshark Wireshark=3.4.1
Oracle ZFS Storage Appliance Kit=8.8
Remediation
Patch Available
Event History
Dec 21, 2020
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26422?
CVE-2020-26422 is classified as a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2020-26422?
The fix for CVE-2020-26422 involves upgrading to Wireshark version 3.4.2 or later.
3
What impact does CVE-2020-26422 have on affected versions of Wireshark?
CVE-2020-26422 allows denial of service via packet injection or crafted capture files, affecting versions 3.4.0 and 3.4.1.
4
Is CVE-2020-26422 present in other software besides Wireshark?
Yes, CVE-2020-26422 also affects Oracle Sun ZFS Storage Appliance Kit version 8.8.
5
How can I determine if I am vulnerable to CVE-2020-26422?
You are vulnerable to CVE-2020-26422 if you are using Wireshark versions 3.4.0 or 3.4.1 without applying the official patch.