Описание
Security update for wireshark
This update for wireshark fixes the following issues:
Update to Wireshark 2.4.11 (bsc#1117740).
Security issues fixed:
- CVE-2018-19625: The Wireshark dissection engine could crash (wnpa-sec-2018-51)
- CVE-2018-19626: The DCOM dissector could crash (wnpa-sec-2018-52)
- CVE-2018-19623: The LBMPDM dissector could crash (wnpa-sec-2018-53)
- CVE-2018-19622: The MMSE dissector could go into an infinite loop (wnpa-sec-2018-54)
- CVE-2018-19627: The IxVeriWave file parser could crash (wnpa-sec-2018-55)
- CVE-2018-19624: The PVFS dissector could crash (wnpa-sec-2018-56)
Further bug fixes and updated protocol support as listed in:
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP4
Ссылки
- Link for SUSE-SU-2018:4298-1
- E-Mail link for SUSE-SU-2018:4298-1
- SUSE Security Ratings
- SUSE Bug 1117740
- SUSE CVE CVE-2018-19622 page
- SUSE CVE CVE-2018-19623 page
- SUSE CVE CVE-2018-19624 page
- SUSE CVE CVE-2018-19625 page
- SUSE CVE CVE-2018-19626 page
- SUSE CVE CVE-2018-19627 page
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows.
Затронутые продукты
Ссылки
- CVE-2018-19622
- SUSE Bug 1117740
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm.c by disallowing certain negative values.
Затронутые продукты
Ссылки
- CVE-2018-19623
- SUSE Bug 1117740
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.
Затронутые продукты
Ссылки
- CVE-2018-19624
- SUSE Bug 1117740
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.
Затронутые продукты
Ссылки
- CVE-2018-19625
- SUSE Bug 1117740
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.
Затронутые продукты
Ссылки
- CVE-2018-19626
- SUSE Bug 1117740
Описание
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
Затронутые продукты
Ссылки
- CVE-2018-19627
- SUSE Bug 1117740