CVEs Blog | G5 Cyber Security

CVE-2020-25866 – In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissec

In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25866

Reference (s):

Exit mobile version