| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0281: Updated wireshark package fixes security vulnerabilities |
| Date: |
| Thu, 19 Sep 2013 11:35:47 +0200 |
| Message-ID: |
| <20130919093547.C121F5B0A2@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0281 - Updated wireshark package fixes security vulnerabilities
Publication date: 19 Sep 2013
URL: http://advisories.mageia.org/MGASA-2013-0281.html
Type: security
Affected Mageia releases: 2
CVE: CVE-2013-5719,
CVE-2013-5720,
CVE-2013-5721,
CVE-2013-5722
Description:
The ASSA R3 dissector could go into an infinite loop (CVE-2013-5719).
The RTPS dissector could overflow a buffer (CVE-2013-5720).
The MQ dissector could crash (CVE-2013-5721).
The LDAP dissector could crash (CVE-2013-5722).
The Netmon file parser could crash (wpna-sec-2013-60).
References:
- https://bugs.mageia.org/show_bug.cgi?id=11214
- http://www.wireshark.org/security/wnpa-sec-2013-55.html
- http://www.wireshark.org/security/wnpa-sec-2013-56.html
- http://www.wireshark.org/security/wnpa-sec-2013-57.html
- http://www.wireshark.org/security/wnpa-sec-2013-58.html
- http://www.wireshark.org/security/wnpa-sec-2013-59.html
- http://www.wireshark.org/security/wnpa-sec-2013-60.html
- http://www.wireshark.org/docs/relnotes/wireshark-1.8.10.html
- http://www.wireshark.org/news/20130910.html
- http://www.openwall.com/lists/oss-security/2013/09/11/1
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5719
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5720
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5721
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5722
SRPMS:
- 2/core/wireshark-1.8.10-1.mga2
(
Log in to post comments)