Candidate: CVE-2020-26421 PublicDate: 2020-12-11 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26421 https://gitlab.com/wireshark/wireshark/-/issues/16958 https://www.wireshark.org/security/wnpa-sec-2020-17.html https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26421.json https://gitlab.com/wireshark/wireshark/-/commit/61f17d3c2112f5a9da40a33417b778bf66a10aee Description: Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L [5.3 MEDIUM] Patches_wireshark: upstream_wireshark: released (3.4.1-1) precise/esm_wireshark: DNE trusty_wireshark: ignored (out of standard support) trusty/esm_wireshark: needed xenial_wireshark: ignored (end of standard support, was needed) bionic_wireshark: needed focal_wireshark: needed groovy_wireshark: ignored (reached end-of-life) hirsute_wireshark: not-affected (3.4.4-1ubuntu1) impish_wireshark: not-affected (3.4.4-1ubuntu1) jammy_wireshark: not-affected (3.4.4-1ubuntu1) devel_wireshark: not-affected (3.4.4-1ubuntu1)