Vulnerability Name:

CVE-2020-26422 (CCN-193473)

Assigned:2020-12-18
Published:2020-12-18
Updated:2022-09-02
Summary:Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-120
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-26422

Source: XF
Type: UNKNOWN
wireshark-cve202026422-dos(193473)

Source: CONFIRM
Type: Third Party Advisory
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26422.json

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://gitlab.com/wireshark/wireshark/-/issues/17073

Source: GENTOO
Type: Third Party Advisory
GLSA-202101-12

Source: MISC
Type: Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html

Source: CCN
Type: Wireshark advisory wnpa-sec-2020-20
QUIC dissector crash

Source: MISC
Type: Vendor Advisory
https://www.wireshark.org/security/wnpa-sec-2020-20.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:wireshark:wireshark:3.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:wireshark:wireshark:3.4.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:wireshark:wireshark:3.4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7698
    P
    libwireshark15-3.6.13-150000.3.89.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7983
    P
    wireshark-devel-3.6.13-150000.3.89.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:729
    P
    Security update for MozillaFirefox (Important)
    2022-09-05
    oval:org.opensuse.security:def:95297
    P
    Security update for python-M2Crypto (Important)
    2022-08-05
    oval:org.opensuse.security:def:3630
    P
    Security update for pcre2 (Important)
    2022-07-12
    oval:org.opensuse.security:def:3445
    P
    binutils-2.32-9.36.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3106
    P
    ibus-chewing-1.4.14-4.11 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3360
    P
    rzsz-0.12.21~rc-1001.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94736
    P
    libwireshark15-3.6.2-3.71.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94557
    P
    gd-devel-2.2.5-11.3.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94990
    P
    wireshark-devel-3.6.2-3.71.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94781
    P
    perl-XML-LibXML-2.0132-1.20 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:99488
    P
    (Moderate)
    2022-02-21
    oval:org.opensuse.security:def:102010
    P
    Security update for the Linux Kernel (Live Patch 6 for SLE 15 SP3) (Critical)
    2022-02-17
    oval:org.opensuse.security:def:112915
    P
    libwireshark14-3.4.8-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99687
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:106372
    P
    libwireshark14-3.4.8-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:99995
    P
    (Important)
    2021-09-23
    oval:org.opensuse.security:def:101494
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:101270
    P
    graphviz-perl-2.40.1-6.6.8 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:111597
    P
    Security update for wireshark (Important)
    2021-07-10
    oval:org.opensuse.security:def:111454
    P
    Security update for wireshark, libvirt, sbc, libqt5-qtmultimedia (Important)
    2021-06-24
    oval:org.opensuse.security:def:73656
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:8791
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:108676
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:92538
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:97130
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:69679
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:117674
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:75906
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:101703
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:9738
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:4199
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:93242
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:91952
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:65288
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:73841
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:8986
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:98902
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:92737
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:69878
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:64534
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:10108
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:5749
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:107936
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:92147
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:66838
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:74293
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:9354
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:99097
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:92936
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:70248
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:64719
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:10289
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:8610
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:108160
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:92339
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:69494
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:117451
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:74356
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:101460
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:9539
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:99289
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:4136
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:93089
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:70429
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:65225
    P
    Security update for wireshark (Important)
    2021-06-22
    BACK
    wireshark wireshark 3.4.0
    wireshark wireshark 3.4.1
    oracle zfs storage appliance kit 8.8
    wireshark wireshark 3.4.0