In Wireshark 3.2.0 to 3.2.1, the WireGuard dissector could crash. This was addressed in epan/dissectors/packet-wireguard.c by handling the situation where a certain data structure intentionally has a NULL value.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Feb 27, 2020 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Jul 28, 2020 | Feb 27, 2020 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/wireshark-common to version 2.6.15-11.4.20.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark/tshark to version 2.6.15-11.4.20.0.1.2.0 on Solaris 11.4Upgrade diagnostic/wireshark to version 2.6.15-11.4.20.0.1.2.0 on Solaris 11.4 | Jan 19, 2021 | Feb 27, 2020 |
| Suse | — | Upgrade libspandsp2Upgrade spandsp-develUpgrade libmaxminddb0-32bitUpgrade libwsutil11Upgrade spandsp-docUpgrade mmdblookupUpgrade libwireshark13Upgrade libspandsp2-32bitUpgrade libmaxminddb0Upgrade libmaxminddb-develUpgrade wiresharkUpgrade wireshark-ui-qtUpgrade libwiretap10Upgrade wireshark-devel | Mar 17, 2020 | Feb 27, 2020 |
| Wireshark | — | Upgrade to Wireshark version 3.2.2 | Mar 2, 2020 | Feb 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub