Bug 991017 (CVE-2016-6508)

Summary: VUL-1: CVE-2016-6508: wireshark: RLC long loop (wnpa-sec-2016-44)
Product: [Novell Products] SUSE Security Incidents Reporter: Andreas Stieger <astieger>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: cyliu, lszhu
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: CVSSv2:SUSE:CVE-2016-6508:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P) CVSSv2:RedHat:CVE-2016-6508:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P) CVSSv3:RedHat:CVE-2016-6508:5.9:(AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) CVSSv2:NVD:CVE-2016-6508:4.3:(AV:N/AC:M/Au:N/C:N/I:N/A:P) CVSSv3:NVD:CVE-2016-6508:5.9:(AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Andreas Stieger 2016-07-28 09:58:53 UTC
Wireshark 2.0.5 and 1.12.13
https://www.wireshark.org/lists/wireshark-announce/201607/msg00001.html
https://www.wireshark.org/lists/wireshark-announce/201607/msg00002.html

The RLC dissector could go into a long loop. It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Affects  2.0.0 to 2.0.4, 1.12.0 to 1.12.12, fixed in 2.0.5, 1.12.13.
https://www.wireshark.org/security/wnpa-sec-2016-44.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12624
Comment 1 Swamp Workflow Management 2016-07-28 22:00:56 UTC
bugbot adjusting priority
Comment 2 Bernhard Wiedemann 2016-07-28 22:01:22 UTC
This is an autogenerated message for OBS integration:
This bug (991017) was mentioned in
https://build.opensuse.org/request/show/415693 Factory / wireshark
https://build.opensuse.org/request/show/415701 13.2+42.1 / wireshark
Comment 3 Bernhard Wiedemann 2016-08-01 20:01:10 UTC
This is an autogenerated message for OBS integration:
This bug (991017) was mentioned in
https://build.opensuse.org/request/show/416463 Factory / wireshark
https://build.opensuse.org/request/show/416464 13.2+42.1 / wireshark
Comment 4 Swamp Workflow Management 2016-08-05 22:09:56 UTC
openSUSE-SU-2016:1974-1: An update that fixes 8 vulnerabilities is now available.

Category: security (low)
Bug References: 991012,991013,991015,991016,991017,991018,991019,991020
CVE References: CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511
Sources used:
openSUSE Leap 42.1 (src):    wireshark-1.12.13-29.1
openSUSE 13.2 (src):    wireshark-1.12.13-44.1
Comment 5 Lingshan Zhu 2016-08-19 09:16:41 UTC
It seems to be https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12660,
it is fixed in git tag 1.12.13, commit 604b8929f3ca540862de4f539fae848abb78dfb6, will update to 1.12.13
Comment 6 Lingshan Zhu 2016-08-22 07:33:13 UTC
MR sent to SLES11 Update and SLES12 Update:
https://build.suse.de/request/show/119844
https://build.suse.de/request/show/119843

Assigned to security-team@suse.de, please re-assign this bug to me after you finished you work, for my track.Thanks
Comment 7 Lingshan Zhu 2016-08-22 07:33:20 UTC
MR sent to SLES11 Update and SLES12 Update:
https://build.suse.de/request/show/119844
https://build.suse.de/request/show/119843

Assigned to security-team@suse.de, please re-assign this bug to me after you finished you work, for my track.Thanks
Comment 8 Swamp Workflow Management 2016-09-02 10:11:17 UTC
SUSE-SU-2016:2212-1: An update that fixes 18 vulnerabilities is now available.

Category: security (moderate)
Bug References: 983671,991012,991013,991015,991016,991017,991018,991019,991020
CVE References: CVE-2016-5350,CVE-2016-5351,CVE-2016-5352,CVE-2016-5353,CVE-2016-5354,CVE-2016-5355,CVE-2016-5356,CVE-2016-5357,CVE-2016-5358,CVE-2016-5359,CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    wireshark-1.12.13-0.23.1
SUSE Linux Enterprise Server 11-SP4 (src):    wireshark-1.12.13-0.23.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    wireshark-1.12.13-0.23.1
Comment 10 Swamp Workflow Management 2016-10-04 19:10:03 UTC
SUSE-SU-2016:2453-1: An update that fixes 18 vulnerabilities is now available.

Category: security (moderate)
Bug References: 983671,991012,991013,991015,991016,991017,991018,991019,991020
CVE References: CVE-2016-5350,CVE-2016-5351,CVE-2016-5352,CVE-2016-5353,CVE-2016-5354,CVE-2016-5355,CVE-2016-5356,CVE-2016-5357,CVE-2016-5358,CVE-2016-5359,CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP1 (src):    wireshark-1.12.13-31.1
SUSE Linux Enterprise Server 12-SP1 (src):    wireshark-1.12.13-31.1
SUSE Linux Enterprise Desktop 12-SP1 (src):    wireshark-1.12.13-31.1