Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3165-1

Опубликовано: 09 сент. 2024
Источник: suse-cvrf

Описание

Security update for wireshark

This update for wireshark fixes the following issues:

wireshark was updated from version 3.6.23 to version 4.2.6 (jsc#PED-8517):

  • Security issues fixed with this update:

    • CVE-2024-0207: HTTP3 dissector crash (bsc#1218503)
    • CVE-2024-0210: Zigbee TLV dissector crash (bsc#1218506)
    • CVE-2024-0211: DOCSIS dissector crash (bsc#1218507)
    • CVE-2023-6174: Fixed SSH dissector crash (bsc#1217247)
    • CVE-2023-6175: NetScreen file parser crash (bsc#1217272)
    • CVE-2023-5371: RTPS dissector memory leak (bsc#1215959)
    • CVE-2023-3649: iSCSI dissector crash (bsc#1213318)
    • CVE-2023-2854: BLF file parser crash (bsc#1211708)
    • CVE-2023-0666: RTPS dissector crash (bsc#1211709)
    • CVE-2023-0414: EAP dissector crash (bsc#1207666)
  • Major changes introduced with versions 4.2.0 and 4.0.0:

  • Added an aditional desktopfile to start wireshark which asks for the super user password.

Список пакетов

Image SLES15-SP6-SAP-Azure-LI-BYOS
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP6
wireshark-devel-4.2.6-150600.18.6.1
wireshark-ui-qt-4.2.6-150600.18.6.1
openSUSE Leap 15.6
libwireshark17-4.2.6-150600.18.6.1
libwiretap14-4.2.6-150600.18.6.1
libwsutil15-4.2.6-150600.18.6.1
wireshark-4.2.6-150600.18.6.1
wireshark-devel-4.2.6-150600.18.6.1
wireshark-ui-qt-4.2.6-150600.18.6.1

Описание

Crash in the EAP dissector in Wireshark 4.0.0 to 4.0.2 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

HTTP3 dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

Zigbee TLV dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

DOCSIS dissector crash in Wireshark 4.2.0 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки

Описание

T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file


Затронутые продукты
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwireshark17-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwiretap14-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:libwsutil15-4.2.6-150600.18.6.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production:wireshark-4.2.6-150600.18.6.1

Ссылки
Уязвимость SUSE-SU-2024:3165-1