Описание
Security update for wireshark
This update for wireshark fixes the following issues:
- Updated to version 3.6.11 (bsc#1207447):
- CVE-2023-0417: Fixed a memory leak in the NFS dissector (bsc#1207669).
- CVE-2023-0413: Fixed a crash in the dissection engine (bsc#1207665).
- CVE-2023-0416: Fixed a crash in the GNW dissector (bsc#1207668).
- CVE-2023-0415: Fixed a crash in the iSCSI dissector (bsc#1207667).
- CVE-2023-0411: Fixed several issues where an excessive CPU consumption could be triggered in multiple dissectors (bsc#1207663).
- CVE-2023-0412: Fixed a crash in the TIPC dissector (bsc#1207664).
Список пакетов
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP4-SAP-Azure-LI-BYOS
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
Image SLES15-SP4-SAP-Azure-VLI-BYOS
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP5-SAP-Azure-LI-BYOS
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
Image SLES15-SP5-SAP-Azure-VLI-BYOS
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Enterprise Storage 6
SUSE Enterprise Storage 7
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise Module for Basesystem 15 SP4
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
SUSE Linux Enterprise Real Time 15 SP3
SUSE Linux Enterprise Server 15 SP1-LTSS
SUSE Linux Enterprise Server 15 SP2-LTSS
SUSE Linux Enterprise Server 15 SP3-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Retail Branch Server 4.2
SUSE Manager Server 4.2
openSUSE Leap 15.4
Ссылки
- Link for SUSE-SU-2023:0343-1
- E-Mail link for SUSE-SU-2023:0343-1
- SUSE Security Ratings
- SUSE Bug 1206189
- SUSE Bug 1207447
- SUSE Bug 1207663
- SUSE Bug 1207664
- SUSE Bug 1207665
- SUSE Bug 1207667
- SUSE Bug 1207668
- SUSE Bug 1207669
- SUSE CVE CVE-2022-4345 page
- SUSE CVE CVE-2023-0411 page
- SUSE CVE CVE-2023-0412 page
- SUSE CVE CVE-2023-0413 page
- SUSE CVE CVE-2023-0415 page
- SUSE CVE CVE-2023-0416 page
- SUSE CVE CVE-2023-0417 page
Описание
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2022-4345
- SUSE Bug 1207080
Описание
Excessive loops in multiple dissectors in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0411
- SUSE Bug 1207663
Описание
TIPC dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0412
- SUSE Bug 1207664
Описание
Dissection engine bug in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0413
- SUSE Bug 1207665
Описание
iSCSI dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0415
- SUSE Bug 1207667
Описание
GNW dissector crash in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0416
- SUSE Bug 1207668
Описание
Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file
Затронутые продукты
Ссылки
- CVE-2023-0417
- SUSE Bug 1207669