CVE-2020-7044: High severity Wireshark Wireshark vulnerability
Published Jan 16, 2020
·Updated
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
Affected Software
7 affected components
Wireshark Wireshark>=3.2.0<3.2.1
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
Oracle ZFS Storage Appliance Kit=8.8
Oracle Solaris=11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wireshark/wasp dissectorto a version that resolves this vulnerability.Fixed in 3.2.1Patch epan/dissectors/packet-wassp.c
Event History
Jan 16, 2020
CVE Published
via MITRE·03:05 AM
Data Sourced
via MITRE·03:05 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7044?
CVE-2020-7044 is classified as a medium severity vulnerability that can cause a crash in Wireshark.
2
How do I fix CVE-2020-7044?
To fix CVE-2020-7044, update Wireshark to version 3.2.1 or later.
3
Which versions of Wireshark are affected by CVE-2020-7044?
Wireshark versions 3.2.0 and earlier are affected by CVE-2020-7044.
4
What impact does CVE-2020-7044 have on affected systems?
CVE-2020-7044 can cause a denial of service due to a crash when processing certain packets.
5
Is there a workaround for CVE-2020-7044 if I cannot update?
There is no official workaround for CVE-2020-7044; updating to the patched version is recommended.