CVE-2020-25866
Summary
| CVE | CVE-2020-25866 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-06 15:15:00 UTC |
| Updated | 2023-11-07 03:20:00 UTC |
| Description | In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| BLIP: Fix decompression buffer bug (4a948427) · Commits · Wireshark Foundation / wireshark · GitLab |
MISC |
gitlab.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 33 Update: wireshark-3.2.7-2.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 32 Update: wireshark-3.2.7-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| BLIP: Static decompression buffer is of insufficient size (#16866) · Issues · Wireshark Foundation / wireshark · GitLab |
MISC |
gitlab.com |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 32 Update: wireshark-3.2.7-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:1882-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] Fedora 31 Update: wireshark-3.2.7-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: wireshark-3.2.7-2.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:1878-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [SECURITY] Fedora 31 Update: wireshark-3.2.7-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - January 2021 |
MISC |
www.oracle.com |
|
| Wireshark · wnpa-sec-2020-13 · BLIP dissector crash |
MISC |
www.wireshark.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296071 Oracle Solaris 11.4 Support Repository Update (SRU) 27.82.1 Missing (CPUOCT2020)
- 501328 Alpine Linux Security Update for wireshark