Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:0722-1

Опубликовано: 04 мар. 2022
Источник: suse-cvrf

Описание

Security update for wireshark

This update for wireshark fixes the following issues:

Update to Wireshark 3.6.2:

  • CVE-2022-0586: RTMPT dissector infinite loop (bsc#1195866)
  • CVE-2022-0585: Large loops in multiple dissectors (bsc#1195867)
  • CVE-2022-0583: PVFS dissector crash (bsc#1195868)
  • CVE-2022-0582: CSN.1 dissector crash (bsc#1195869)
  • CVE-2022-0581: CMS dissector crash (bsc#1195870)

Список пакетов

openSUSE Leap 15.3
libwireshark15-3.6.2-3.71.1
libwiretap12-3.6.2-3.71.1
libwsutil13-3.6.2-3.71.1
wireshark-3.6.2-3.71.1
wireshark-devel-3.6.2-3.71.1
wireshark-ui-qt-3.6.2-3.71.1

Описание

Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file


Затронутые продукты
openSUSE Leap 15.3:libwireshark15-3.6.2-3.71.1
openSUSE Leap 15.3:libwiretap12-3.6.2-3.71.1
openSUSE Leap 15.3:libwsutil13-3.6.2-3.71.1
openSUSE Leap 15.3:wireshark-3.6.2-3.71.1

Ссылки

Описание

Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file


Затронутые продукты
openSUSE Leap 15.3:libwireshark15-3.6.2-3.71.1
openSUSE Leap 15.3:libwiretap12-3.6.2-3.71.1
openSUSE Leap 15.3:libwsutil13-3.6.2-3.71.1
openSUSE Leap 15.3:wireshark-3.6.2-3.71.1

Ссылки

Описание

Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file


Затронутые продукты
openSUSE Leap 15.3:libwireshark15-3.6.2-3.71.1
openSUSE Leap 15.3:libwiretap12-3.6.2-3.71.1
openSUSE Leap 15.3:libwsutil13-3.6.2-3.71.1
openSUSE Leap 15.3:wireshark-3.6.2-3.71.1

Ссылки

Описание

Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file


Затронутые продукты
openSUSE Leap 15.3:libwireshark15-3.6.2-3.71.1
openSUSE Leap 15.3:libwiretap12-3.6.2-3.71.1
openSUSE Leap 15.3:libwsutil13-3.6.2-3.71.1
openSUSE Leap 15.3:wireshark-3.6.2-3.71.1

Ссылки

Описание

Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file


Затронутые продукты
openSUSE Leap 15.3:libwireshark15-3.6.2-3.71.1
openSUSE Leap 15.3:libwiretap12-3.6.2-3.71.1
openSUSE Leap 15.3:libwsutil13-3.6.2-3.71.1
openSUSE Leap 15.3:wireshark-3.6.2-3.71.1

Ссылки
Уязвимость openSUSE-SU-2022:0722-1