USN-6262-1
Dashboard / Vulnerabilities / USN-6262-1
USN-6262-1
Summary: wireshark vulnerabilities
Details: It was discovered that Wireshark did not properly handle certain NFS packages when certain configuration options were enabled. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-13164) It was discovered that Wireshark did not properly handle certain GVCP packages. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-15466) It was discovered that Wireshark did not properly handle certain Kafka packages. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-17498) It was discovered that Wireshark did not properly handle certain TCP packages containing an invalid 0xFFFF checksum. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-25862) It was discovered that Wireshark did not properly handle certain MIME packages containing invalid parts. An attacker could possibly use this issue to cause Wireshark to crash, resulting in a denial of service. (CVE-2020-25863)
References: https://ubuntu.com/security/notices/USN-6262-1, https://ubuntu.com/security/CVE-2020-13164, https://ubuntu.com/security/CVE-2020-15466, https://ubuntu.com/security/CVE-2020-17498, https://ubuntu.com/security/CVE-2020-25862, https://ubuntu.com/security/CVE-2020-25863
Affected packages
Package
Name: wireshark
Purl: pkg:deb/ubuntu/wireshark?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
