CVE-2020-7045: Null Pointer Dereference
Published Jan 16, 2020
·Updated
In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by validating opcodes.
Affected Software
2 affected components
Wireshark Wireshark>=3.0.0<3.0.8
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jan 16, 2020
CVE Published
via MITRE·03:07 AM
Data Sourced
via MITRE·03:07 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7045?
CVE-2020-7045 is classified as a medium severity vulnerability due to the potential for the Wireshark application to crash.
2
How do I fix CVE-2020-7045?
To fix CVE-2020-7045, upgrade Wireshark to version 3.0.8 or later.
3
Which versions of Wireshark are affected by CVE-2020-7045?
CVE-2020-7045 affects Wireshark versions prior to 3.0.8, specifically the 3.0.x series.
4
Does CVE-2020-7045 affect Debian Linux?
Yes, CVE-2020-7045 affects Debian Linux 9.0 when running an affected version of Wireshark.
5
What component of Wireshark is impacted by CVE-2020-7045?
CVE-2020-7045 impacts the BT ATT dissector component of Wireshark.