MEDIUM
wireshark: USB HID dissector crash (wnpa-sec-2020-17)
Published Dec 11, 2020
5.9
MEDIUMCVSS 3.1
EPSS 2.55%
Description
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
Affected products
-
- Version 3.4.0StatusaffectedConstraints-
- Version >= 3.2.0 to < 3.2.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Wireshark Foundation | Wireshark | n/a |
|
Configuration 1
Configuration 2
OR
- 32
- 33
Configuration 3
- 9.0
Configuration 4
- 8.8
No data.
Red Hat Enterprise Linux 6
wireshark
Out of support scope
Red Hat Enterprise Linux 7
wireshark
Out of support scope
Red Hat Enterprise Linux 8
wireshark
Fix deferred
Red Hat Enterprise Linux 9
wireshark
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | wireshark | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | wireshark | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | wireshark | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- https://access.redhat.com/security/cve/CVE-2020-26421 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1919923 Issue Tracking
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26421.json x_refsource_CONFIRMThird Party Advisory
- https://gitlab.com/wireshark/wireshark/-/issues/16958 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00008.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M75HYXU36SP6GHIDPHNZGJKEO6TX4C4Y/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YHWDZPWQJMLK64VFDWJC5SEGPNH6Y72Z/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-26421
- https://security.gentoo.org/glsa/202101-12 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-26421
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.wireshark.org/security/wnpa-sec-2020-17
- https://www.wireshark.org/security/wnpa-sec-2020-17.html x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Dec 11, 2020
Updated Aug 4, 2024
Reserved Oct 1, 2020
Link CVE-2020-26421
CISA Vulnrichment
Updated n/a