Wireshark Updates
2670Warning Date
Severity Level
Warning Number
Target Sector
27 February, 2020
● Medium
2020-967
All
Description:
Wireshark has released security updates to address multiple vulnerabilities in the following versions:
- From 3.2.0 to 3.2.1
- From 3.0.0 to 3.0.8
- From 2.6.0 to 2.6.14
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Consume excessive CPU resources by LTE RRC dissector.
- Crash WiMax DLMAP dissector, EAP dissector and WireGuard dissector.
By Injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Best practice and Recommendations:
The CERT team encourages users to review Wireshark security advisory and apply the necessary updates: