Описание
Security update for wireshark
This update for wireshark fixes the following issues:
- Update to wireshark 3.2.7:
- CVE-2020-25863: MIME Multipart dissector crash (bsc#1176908)
- CVE-2020-25862: TCP dissector crash (bsc#1176909)
- CVE-2020-25866: BLIP dissector crash (bsc#1176910)
- CVE-2020-17498: Kafka dissector crash (bsc#1175204)
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.2
Ссылки
- E-Mail link for openSUSE-SU-2020:1882-1
- SUSE Security Ratings
- SUSE Bug 1175204
- SUSE Bug 1176908
- SUSE Bug 1176909
- SUSE Bug 1176910
- SUSE CVE CVE-2020-17498 page
- SUSE CVE CVE-2020-25862 page
- SUSE CVE CVE-2020-25863 page
- SUSE CVE CVE-2020-25866 page
Описание
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
Затронутые продукты
Ссылки
- CVE-2020-17498
- SUSE Bug 1175204
Описание
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
Затронутые продукты
Ссылки
- CVE-2020-25862
- SUSE Bug 1176909
Описание
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
Затронутые продукты
Ссылки
- CVE-2020-25863
- SUSE Bug 1176908
Описание
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.
Затронутые продукты
Ссылки
- CVE-2020-25866
- SUSE Bug 1176910