Learn about CVE-2020-13164 impacting Wireshark versions 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16. Find out how to prevent a crash in the NFS dissector.
Wireshark versions 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16 are affected by a vulnerability in the NFS dissector that could lead to a crash. The issue has been resolved by preventing excessive recursion.
Understanding CVE-2020-13164
Wireshark vulnerability impacting NFS dissector
What is CVE-2020-13164?
This CVE refers to a vulnerability in Wireshark versions 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16 that could cause the NFS dissector to crash due to excessive recursion.
The Impact of CVE-2020-13164
Technical Details of CVE-2020-13164
Details of the vulnerability
Vulnerability Description
The vulnerability in Wireshark's NFS dissector could result in a crash due to excessive recursion, particularly in scenarios involving a cycle in the directory graph on a filesystem.
Affected Systems and Versions
Exploitation Mechanism
Attackers could exploit this vulnerability by crafting malicious NFS packets to trigger the excessive recursion in the NFS dissector, leading to a crash.
Mitigation and Prevention
Protecting against CVE-2020-13164
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates