Back

HIGH

wireshark: injecting a malformed packet may cause the EAP dissector to crash due to out-of-bounds read

Published Feb 27, 2020

Description

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.

Affected products

Remediation

No remediation recorded yet.

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 27, 2020
Updated Aug 4, 2024
Reserved Feb 27, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 26, 2020
Bugzilla 1814622

ENISA EUVD

Assigner mitre
Published Feb 27, 2020
Updated Aug 4, 2024

GitHub

No data