Candidate: CVE-2020-26419 PublicDate: 2020-12-11 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26419 https://gitlab.com/wireshark/wireshark/-/issues/17032 https://www.wireshark.org/security/wnpa-sec-2020-19.html https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26419.json https://gitlab.com/wireshark/wireshark/-/merge_requests/1107/diffs?commit_id=5edf715c04e6091ba4f359fd33a95e9e830fd001 Description: Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L [5.3 MEDIUM] Patches_wireshark: upstream_wireshark: released (3.4.1-1) precise/esm_wireshark: DNE trusty_wireshark: ignored (out of standard support) trusty/esm_wireshark: not-affected (code not present) xenial_wireshark: not-affected (code not present) bionic_wireshark: not-affected (code not present) focal_wireshark: not-affected (code not present) groovy_wireshark: not-affected (code not present) hirsute_wireshark: not-affected (3.4.4-1ubuntu1) devel_wireshark: not-affected (3.4.4-1ubuntu1)