Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:2730-1

Опубликовано: 16 окт. 2017
Источник: suse-cvrf

Описание

Security update for wireshark

This update for wireshark to version 2.2.10 fixes multiple minor security issues.

These vulnerabilities that could be used to trigger dissector crashes or infinite loops by making Wireshark read specially crafted packages from the network or a capture file:

  • CVE-2017-15192: BT ATT dissector crash
  • CVE-2017-15193: MBIM dissector crash
  • CVE-2017-15191: DMP dissector crash

Список пакетов

openSUSE Leap 42.2
wireshark-2.2.10-24.1
wireshark-devel-2.2.10-24.1
wireshark-ui-gtk-2.2.10-24.1
wireshark-ui-qt-2.2.10-24.1
openSUSE Leap 42.3
wireshark-2.2.10-24.1
wireshark-devel-2.2.10-24.1
wireshark-ui-gtk-2.2.10-24.1
wireshark-ui-qt-2.2.10-24.1

Описание

In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.


Затронутые продукты
openSUSE Leap 42.2:wireshark-2.2.10-24.1
openSUSE Leap 42.2:wireshark-devel-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-gtk-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-qt-2.2.10-24.1

Ссылки

Описание

In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.


Затронутые продукты
openSUSE Leap 42.2:wireshark-2.2.10-24.1
openSUSE Leap 42.2:wireshark-devel-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-gtk-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-qt-2.2.10-24.1

Ссылки

Описание

In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.


Затронутые продукты
openSUSE Leap 42.2:wireshark-2.2.10-24.1
openSUSE Leap 42.2:wireshark-devel-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-gtk-2.2.10-24.1
openSUSE Leap 42.2:wireshark-ui-qt-2.2.10-24.1

Ссылки