vulnerability
Wireshark : CVE-2020-25862 : TCP dissector crash
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Sep 24, 2020 | Sep 24, 2020 | Oct 13, 2020 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Sep 24, 2020
Added
Sep 24, 2020
Modified
Oct 13, 2020
Description
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
Solution(s)
wireshark-upgrade-2_6_20wireshark-upgrade-3_0_14wireshark-upgrade-3_2_7

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.