ArchLinux: 202007-2: wireshark-cli: denial of service
Summary
An infinite loop has been found in the GVCP dissector of Wireshark before 3.2.5. It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Resolution
Upgrade to 3.2.5-1.
# pacman -Syu "wireshark-cli>=3.2.5-1"
The problem has been fixed upstream in version 3.2.5.
References
https://www.wireshark.org/security/wnpa-sec-2020-09 https://gitlab.com/wireshark/wireshark/-/issues/16029 https://security.archlinux.org/CVE-2020-15466
Workaround
None.