Bug 1178290 - VUL-1: wireshark: FBZERO dissector crash (wnpa-sec-2020-14)
VUL-1: wireshark: FBZERO dissector crash (wnpa-sec-2020-14)
Status: RESOLVED DUPLICATE of bug 1177406
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Robert Frohl
Security Team bot
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-10-30 08:25 UTC by Andreas Stieger
Modified: 2020-10-30 12:07 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2020-10-30 08:25:17 UTC
It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Fixed in 3.4.0, 3.2.8 

References:
https://www.wireshark.org/security/wnpa-sec-2020-14
https://gitlab.com/wireshark/wireshark/-/issues/16887
Comment 1 Robert Frohl 2020-10-30 12:07:08 UTC
duplicate of bsc#1177406

*** This bug has been marked as a duplicate of bug 1177406 ***