Bug 889899 - (CVE-2014-5165) VUL-0: CVE-2014-5165: wireshark: ASN.1 BER dissector crash
(CVE-2014-5165)
VUL-0: CVE-2014-5165: wireshark: ASN.1 BER dissector crash
Status: RESOLVED DUPLICATE of bug 889854
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Chunyan Liu
Security Team bot
https://smash.suse.de/issue/104168/
maint:released:sle11-sp3:59031
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-01 07:35 UTC by Victor Pereira
Modified: 2015-02-18 23:15 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-08-01 07:35:41 UTC
CVE-2014-5165

It was reported that Wireshark's ASN.1 BER dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

This is reported to affect Wireshark versions 1.10.0 to 1.10.8. It is fixed in 1.10.9.


References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10187
http://www.wireshark.org/security/wnpa-sec-2014-11.html
https://bugzilla.redhat.com/show_bug.cgi?id=1125761
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5165
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5165
Comment 2 SMASH SMASH 2014-08-01 07:40:11 UTC
Affected packages:

SLE-12: wireshark
Comment 3 Swamp Workflow Management 2014-08-01 22:00:20 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2014-08-04 03:00:57 UTC
This is an autogenerated message for OBS integration:
This bug (889899) was mentioned in
https://build.opensuse.org/request/show/243553 13.1 / wireshark
Comment 5 Chunyan Liu 2014-08-04 04:34:24 UTC
https://build.suse.de/request/show/42102 SLE-12 / wireshark

*** This bug has been marked as a duplicate of bug 889854 ***
Comment 6 Swamp Workflow Management 2014-08-20 07:04:28 UTC
openSUSE-SU-2014:1038-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 889899,889900,889901,889906
CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165
Sources used:
openSUSE 13.1 (src):    wireshark-1.10.9-20.1
Comment 7 Swamp Workflow Management 2014-09-29 08:04:24 UTC
openSUSE-SU-2014:1249-1: An update that fixes 15 vulnerabilities is now available.

Category: security (moderate)
Bug References: 889899,889900,889901,889906,897055
CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165,CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432
Sources used:
openSUSE 13.1 (src):    wireshark-1.10.10-24.1
openSUSE 12.3 (src):    wireshark-1.10.10-1.44.1