First published: Fri Oct 30 2020(Updated: )
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | >=3.2.0<=3.2.7 | |
Debian | =9.0 | |
Fedora | =32 | |
Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28030 has a severity rating that indicates it could lead to crashes in Wireshark due to improper handling in the GQUIC dissector.
To fix CVE-2020-28030, upgrade Wireshark to version 3.2.8 or later to address the crash vulnerability.
CVE-2020-28030 affects Wireshark versions 3.2.0 to 3.2.7.
CVE-2020-28030 also impacts certain versions of Debian Linux (Debian 9.0) and Fedora (versions 32 and 33).
CVE-2020-28030 involves the GQUIC dissector in Wireshark, particularly the implementation of offset advancement.