Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:1974-1

Опубликовано: 05 авг. 2016
Источник: suse-cvrf

Описание

Security update for wireshark

Wireshark was updated to 1.12.13 to fix a number of minor security issues and bugs.

This release fixes a number issues in protocol dissectors that could have allowed a remote attacker to crash Wireshark or cause excessive CPU usage through specially crafted packages inserted into the network or a capture file.

  • CVE-2016-6504: NDS dissector crash (boo#991012)
  • CVE-2016-6505: PacketBB crash (boo#991013)
  • CVE-2016-6506: WSP infinite loop (boo#991015)
  • CVE-2016-6507: MMSE infinite loop (boo#991016)
  • CVE-2016-6508: RLC long loop (boo#991017)
  • CVE-2016-6509: LDSS dissector crash (boo#991018)
  • CVE-2016-6510: RLC dissector crash (boo#991019)
  • CVE-2016-6511: OpenFlow long loop (boo#991020)

This update also includes further bug fixes and updated protocol support as listed in: https://www.wireshark.org/docs/relnotes/wireshark-1.12.13.html

Список пакетов

openSUSE Leap 42.1
wireshark-1.12.13-29.1
wireshark-devel-1.12.13-29.1
wireshark-ui-gtk-1.12.13-29.1
wireshark-ui-qt-1.12.13-29.1

Описание

epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки

Описание

epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet.


Затронутые продукты
openSUSE Leap 42.1:wireshark-1.12.13-29.1
openSUSE Leap 42.1:wireshark-devel-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-gtk-1.12.13-29.1
openSUSE Leap 42.1:wireshark-ui-qt-1.12.13-29.1

Ссылки
Уязвимость openSUSE-SU-2016:1974-1