SB2023073139 - Ubuntu update for wireshark
Published: July 31, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2020-13164)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in NFS dissector. A remote attacker can inject a malformed packet onto the wire or trick a victim to read a malformed packet trace file and perform a denial of service (DoS) attack.
2) Infinite loop (CVE-ID: CVE-2020-15466)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the GVCP dissector. A remote attacker can pass specially crafted packet trace file to the application, consume all available system resources and cause denial of service conditions.
3) Double Free (CVE-ID: CVE-2020-17498)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in Kafka dissector. A remote attacker can pass specially crafted data to the application, trigger double free error and crash the application.
4) Input validation error (CVE-ID: CVE-2020-25862)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the TCP dissector in Wireshark. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
5) Input validation error (CVE-ID: CVE-2020-25863)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the MIME Multipart dissector in Wireshark. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.