Описание
Security update for wireshark
This update for wireshark to version 2.4.14 fixes the following issues:
Security issues fixed:
- CVE-2019-10895: NetScaler file parser crash.
- CVE-2019-10899: SRVLOC dissector crash.
- CVE-2019-10894: GSS-API dissector crash.
- CVE-2019-10896: DOF dissector crash.
- CVE-2019-10901: LDSS dissector crash.
- CVE-2019-10903: DCERPC SPOOLSS dissector crash.
Non-security issue fixed:
- Update to version 2.4.14 (bsc#1131945).
Список пакетов
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP4
Ссылки
- Link for SUSE-SU-2019:1038-1
- E-Mail link for SUSE-SU-2019:1038-1
- SUSE Security Ratings
- SUSE Bug 1131945
- SUSE CVE CVE-2019-10894 page
- SUSE CVE CVE-2019-10895 page
- SUSE CVE CVE-2019-10896 page
- SUSE CVE CVE-2019-10899 page
- SUSE CVE CVE-2019-10901 page
- SUSE CVE CVE-2019-10903 page
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.
Затронутые продукты
Ссылки
- CVE-2019-10894
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.
Затронутые продукты
Ссылки
- CVE-2019-10895
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
Затронутые продукты
Ссылки
- CVE-2019-10896
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.
Затронутые продукты
Ссылки
- CVE-2019-10899
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.
Затронутые продукты
Ссылки
- CVE-2019-10901
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945
Описание
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
Затронутые продукты
Ссылки
- CVE-2019-10903
- SUSE Bug 1131941
- SUSE Bug 1131943
- SUSE Bug 1131945