CVE-2020-26575: High severity wireshark vulnerability
Published Oct 6, 2020
·Updated
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
Affected Software
6 affected components
Wireshark Wireshark<=3.2.7
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Oracle Zfs Storage Appliance Firmware=8.8
Oracle ZFS Storage Appliance
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 6, 2020
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26575?
CVE-2020-26575 is a vulnerability in Wireshark through 3.2.7 that allows the Facebook Zero Protocol dissector to enter an infinite loop.
2
How severe is CVE-2020-26575?
CVE-2020-26575 has a severity score of 7.5 (High).
3
What software versions are affected by CVE-2020-26575?
Wireshark 3.2.7, Fedora 32, Fedora 33, Debian Linux 9.0, and Oracle ZFS Storage Appliance Firmware 8.8 are affected by CVE-2020-26575.
4
How can CVE-2020-26575 be fixed?
CVE-2020-26575 can be fixed by updating to the latest version of Wireshark (3.2.8 or later).
5
Is Oracle ZFS Storage Appliance vulnerable to CVE-2020-26575?
No, Oracle ZFS Storage Appliance is not vulnerable to CVE-2020-26575.