Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1199-1

Опубликовано: 14 авг. 2020
Источник: suse-cvrf

Описание

Security update for wireshark

This update for wireshark fixes the following issues:

  • Wireshark to 3.2.5:
    • CVE-2020-15466: GVCP dissector infinite loop (bsc#1173606)
    • CVE-2020-13164: NFS dissector crash (bsc#1171899)
    • CVE-2020-11647: The BACapp dissector could crash (bsc#1169063)
  • Further features, bug fixes and updated protocol support as listed in: https://www.wireshark.org/docs/relnotes/wireshark-3.2.5.html

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
libwireshark13-3.2.5-lp152.2.3.1
libwiretap10-3.2.5-lp152.2.3.1
libwsutil11-3.2.5-lp152.2.3.1
wireshark-3.2.5-lp152.2.3.1
wireshark-devel-3.2.5-lp152.2.3.1
wireshark-ui-qt-3.2.5-lp152.2.3.1

Описание

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.


Затронутые продукты
openSUSE Leap 15.2:libwireshark13-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwiretap10-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwsutil11-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:wireshark-3.2.5-lp152.2.3.1

Ссылки

Описание

In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.


Затронутые продукты
openSUSE Leap 15.2:libwireshark13-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwiretap10-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwsutil11-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:wireshark-3.2.5-lp152.2.3.1

Ссылки

Описание

In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.


Затронутые продукты
openSUSE Leap 15.2:libwireshark13-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwiretap10-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:libwsutil11-3.2.5-lp152.2.3.1
openSUSE Leap 15.2:wireshark-3.2.5-lp152.2.3.1

Ссылки