Уязвимость бесконечного цикла в диссекторе протокола Facebook Zero (FBZERO) в Wireshark
Описание
В Wireshark до версии 3.2.7 обнаружена уязвимость, заключающаяся в возможности перехода в бесконечный цикл диссектора протокола Facebook Zero (FBZERO). Эта проблема была решена в epan/dissectors/packet-fbzero.c путем исправления увеличения смещения (offset advancement).
Затронутые версии ПО
- Wireshark версии до 3.2.7
Тип уязвимости
Бесконечный цикл (infinite loop)
Ссылки
- PatchThird Party Advisory
- Broken Link
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- PatchThird Party Advisory
- Broken Link
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
Одновременно
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) di ...
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
Уязвимость функции в epan/dissectors/packet-fbzero.c программного обеспечения Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3
5 Medium
CVSS2