CVE-2020-26575
Gentoo Linux Security Advisory 202011-08
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
En Wireshark versiones hasta 3.2.7, el Facebook Zero Protocol (también se conoce como FBZERO), podría entrar en un bucle infinito. Esto fue abordado en el archivo epan/dissectors/packet-fbzero.c corrigiendo la implementación del avance de compensación
An update that fixes two vulnerabilities is now available. This update for wireshark fixes the following issues. Fixed an issue where FBZERO dissector was entering in infinite loop. Fixed an issue where GQUIC dissector was crashing Infinite memory allocation while parsing this tcp packet This update was imported from the SUSE:SLE-15:Update update project.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-06 CVE Reserved
- 2020-10-06 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://gitlab.com/wireshark/wireshark/-/issues/16887 | Broken Link | |
https://lists.debian.org/debian-lts-announce/2021/02/msg00008.html | Mailing List |
|
https://www.oracle.com/security-alerts/cpujan2021.html | Third Party Advisory |
|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Zfs Storage Appliance Firmware Search vendor "Oracle" for product "Zfs Storage Appliance Firmware" | 8.8 Search vendor "Oracle" for product "Zfs Storage Appliance Firmware" and version "8.8" | - |
Affected
| in | Oracle Search vendor "Oracle" | Zfs Storage Appliance Search vendor "Oracle" for product "Zfs Storage Appliance" | - | - |
Safe
|
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | <= 3.2.7 Search vendor "Wireshark" for product "Wireshark" and version " <= 3.2.7" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 32 Search vendor "Fedoraproject" for product "Fedora" and version "32" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|