Описание
Security update for wireshark
This update for wireshark fixes the following issues:
Wireshark was updated to 2.2.10, fixing security issues and bugs:
- CVE-2017-15191: DMP dissector crash (wnpa-sec-2017-44)
- CVE-2017-15192: BT ATT dissector crash (wnpa-sec-2017-42)
- CVE-2017-15193: MBIM dissector crash (wnpa-sec-2017-43)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
Ссылки
- Link for SUSE-SU-2017:2860-1
- E-Mail link for SUSE-SU-2017:2860-1
- SUSE Security Ratings
- SUSE Bug 1062645
- SUSE CVE CVE-2017-15191 page
- SUSE CVE CVE-2017-15192 page
- SUSE CVE CVE-2017-15193 page
Описание
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
Затронутые продукты
Ссылки
- CVE-2017-15191
- SUSE Bug 1062645
- SUSE Bug 983671
Описание
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.
Затронутые продукты
Ссылки
- CVE-2017-15192
- SUSE Bug 1062645
- SUSE Bug 983671
Описание
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.
Затронутые продукты
Ссылки
- CVE-2017-15193
- SUSE Bug 1062645
- SUSE Bug 983671