|
|
Log in / Subscribe / Register

Mageia alert MGASA-2024-0206 (wireshark)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2024-0206: Updated wireshark packages fix security vulnerabilities
Date:  Mon, 03 Jun 2024 20:31:30 +0200
Message-ID:  <20240603183130.197A4A0D6A@duvel.mageia.org>
Archive-link:  Article

MGASA-2024-0206 - Updated wireshark packages fix security vulnerabilities Publication date: 03 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0206.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-4853, CVE-2024-4854, CVE-2024-4855 Description: Memory handling issue in editcap could cause denial of service via crafted capture file. (CVE-2024-4853) MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file. (CVE-2024-4854) Use after free issue in editcap could cause denial of service via crafted capture file. (CVE-2024-4855) References: - https://bugs.mageia.org/show_bug.cgi?id=33258 - https://lists.fedoraproject.org/archives/list/package-ann... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4853 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4854 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4855 SRPMS: - 9/core/wireshark-4.0.15-1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds