CVE-2020-9429: Null Pointer Dereference
Published Feb 27, 2020
·Updated
In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.
Affected Software
2 affected components
Wireshark Wireshark>=3.2.0<=3.2.1
openSUSE Leap=15.1
Remediation
Event History
Feb 27, 2020
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Wireshark version 3.2.0 to 3.2.1?
The vulnerability ID is CVE-2020-9429.
2
What is the severity level of CVE-2020-9429?
The severity level of CVE-2020-9429 is high with a CVSS score of 7.5.
3
How can the WireGuard dissector crash vulnerability be fixed in Wireshark?
The WireGuard dissector crash vulnerability in Wireshark can be fixed by updating to a version where it has been addressed, such as version 3.2.2 and above.