USN-6262-1: Wireshark vulnerabilities
It was discovered that Wireshark did not properly handle certain NFS packages when certain configuration options were enabled. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-13164) It was discovered that Wireshark did not properly handle certain GVCP packages. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-15466) It was discovered that Wireshark did not properly handle certain Kafka packages. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-17498) It was discovered that Wireshark did not properly handle certain TCP packages containing an invalid 0xFFFF checksum. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-25862) It was discovered that Wireshark did not properly handle certain MIME packages containing invalid parts. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-25863)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this Wireshark vulnerability?
The vulnerability ID for this Wireshark vulnerability is CVE-2020-13164.
How does this vulnerability in Wireshark affect the system?
This vulnerability in Wireshark could allow an attacker to cause the application to crash, resulting in a denial of service.
What is the affected software for this Wireshark vulnerability?
The affected software for this Wireshark vulnerability includes tshark, wireshark, wireshark-qt, wireshark-common, wireshark-gtk, libwireshark13, libwireshark11.
What is the recommended remedy for this Wireshark vulnerability on Ubuntu 20.04?
The recommended remedy for this Wireshark vulnerability on Ubuntu 20.04 is to update to version 3.2.3-1ubuntu0.1~esm1.
Where can I find more information about this Wireshark vulnerability?
You can find more information about this Wireshark vulnerability at the following links: - [CVE-2020-13164](https://ubuntu.com/security/CVE-2020-13164) - [CVE-2020-17498](https://ubuntu.com/security/CVE-2020-17498) - [CVE-2020-15466](https://ubuntu.com/security/CVE-2020-15466)