Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1865-1

Опубликовано: 30 мая 2024
Источник: suse-cvrf

Описание

Security update for wireshark

This update for wireshark fixes the following issues:

Update to version 3.6.22:

  • CVE-2024-4854: MONGO and ZigBee TLV dissector infinite loops (bsc#1224274)
  • CVE-2024-4853: The editcap command line utility could crash when chopping bytes from the beginning of a packet (bsc#1224259)
  • CVE-2024-4855: The editcap command line utility could crash when injecting secrets while writing multiple files (bsc#1224276)

Список пакетов

Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP5
wireshark-devel-3.6.23-150000.3.115.1
wireshark-ui-qt-3.6.23-150000.3.115.1
openSUSE Leap 15.5
libwireshark15-3.6.23-150000.3.115.1
libwiretap12-3.6.23-150000.3.115.1
libwsutil13-3.6.23-150000.3.115.1
wireshark-3.6.23-150000.3.115.1
wireshark-devel-3.6.23-150000.3.115.1
wireshark-ui-qt-3.6.23-150000.3.115.1

Описание

Memory handling issue in editcap could cause denial of service via crafted capture file


Затронутые продукты
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwireshark15-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwiretap12-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwsutil13-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:wireshark-3.6.23-150000.3.115.1

Ссылки

Описание

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwireshark15-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwiretap12-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwsutil13-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:wireshark-3.6.23-150000.3.115.1

Ссылки

Описание

Use after free issue in editcap could cause denial of service via crafted capture file


Затронутые продукты
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwireshark15-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwiretap12-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:libwsutil13-3.6.23-150000.3.115.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production:wireshark-3.6.23-150000.3.115.1

Ссылки
Уязвимость SUSE-SU-2024:1865-1