Revision Date: | 2014-12-01 | Version: | 4 |
Title: | SUSE-SU-2014:1221-1 -- Security update for wireshark |
Description: | The wireshark package was upgraded to 1.10.10 from 1.8.x as 1.8 wasdiscontinued.This update fixes vulnerabilities that could allow an attacker to crashWireshark or make it become unresponsive by sending specific packets ontothe network or have them loaded via a capture file while the dissectorsare running. It also contains a number of other bug fixes. * RTP dissector crash. (wnpa-sec-2014-12 CVE-2014-6421 CVE-2014-6422) * MEGACO dissector infinite loop. (wnpa-sec-2014-13 CVE-2014-6423) * Netflow dissector crash. (wnpa-sec-2014-14 CVE-2014-6424) * RTSP dissector crash. (wnpa-sec-2014-17 CVE-2014-6427) * SES dissector crash. (wnpa-sec-2014-18 CVE-2014-6428) * Sniffer file parser crash. (wnpa-sec-2014-19 CVE-2014-6429 CVE-2014-6430 CVE-2014-6431 CVE-2014-6432) * The Catapult DCT2000 and IrDA dissectors could underrun a buffer. (wnpa-sec-2014-08 CVE-2014-5161 CVE-2014-5162, bnc#889901) * The GSM Management dissector could crash. (wnpa-sec-2014-09 CVE-2014-5163, bnc#889906) * The RLC dissector could crash. (wnpa-sec-2014-10 CVE-2014-5164, bnc#889900) * The ASN.1 BER dissector could crash. (wnpa-sec-2014-11 CVE-2014-5165, bnc#889899)Further bug fixes as listed in:https://www.wireshark.org/docs/relnotes/wireshark-1.10.10.html andhttps://www.wireshark.org/docs/relnotes/wireshark-1.10.9.html .Security Issues: * CVE-2014-5161 * CVE-2014-5162 * CVE-2014-5163 * CVE-2014-5164 * CVE-2014-5165 * CVE-2014-6421 * CVE-2014-6422 * CVE-2014-6423 * CVE-2014-6424 * CVE-2014-6427 * CVE-2014-6428 * CVE-2014-6429 * CVE-2014-6430 * CVE-2014-6431 * CVE-2014-6432 |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2014-5161 CVE-2014-5162 CVE-2014-5163 CVE-2014-5164 CVE-2014-5165 CVE-2014-6421 CVE-2014-6422 CVE-2014-6423 CVE-2014-6424 CVE-2014-6427 CVE-2014-6428 CVE-2014-6429 CVE-2014-6430 CVE-2014-6431 CVE-2014-6432 SUSE-SU-2014:1221-1
|
Platform(s): | SUSE Linux Enterprise Desktop 11 SUSE Linux Enterprise Server 11
| Product(s): | wireshark
|
Definition Synopsis |
Operation system section SUSE Linux Enterprise Server 11.x is installed
OR SUSE Linux Enterprise Desktop 11.x is installed
AND wireshark RPM is earlier than 0:1.10.10-0.2.1
|