Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:0364-1

Опубликовано: 02 фев. 2017
Источник: suse-cvrf

Описание

Security update for Wireshark

This update to Wireshark 2.2.4 fixes two minor vulnerabilities that could be used to cause Wireshark to go into a large or infinite loop by sending specially crafted packages over the network or into a capture file. (bsc#1021739)

Список пакетов

openSUSE Leap 42.2
wireshark-2.2.4-7.1
wireshark-devel-2.2.4-7.1
wireshark-ui-gtk-2.2.4-7.1
wireshark-ui-qt-2.2.4-7.1

Описание

In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow.


Затронутые продукты
openSUSE Leap 42.2:wireshark-2.2.4-7.1
openSUSE Leap 42.2:wireshark-devel-2.2.4-7.1
openSUSE Leap 42.2:wireshark-ui-gtk-2.2.4-7.1
openSUSE Leap 42.2:wireshark-ui-qt-2.2.4-7.1

Ссылки

Описание

In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an integer overflow.


Затронутые продукты
openSUSE Leap 42.2:wireshark-2.2.4-7.1
openSUSE Leap 42.2:wireshark-devel-2.2.4-7.1
openSUSE Leap 42.2:wireshark-ui-gtk-2.2.4-7.1
openSUSE Leap 42.2:wireshark-ui-qt-2.2.4-7.1

Ссылки