Bug 889900 - (CVE-2014-5164) VUL-0:CVE-2014-5164: wireshark: RLC dissector crash
(CVE-2014-5164)
VUL-0:CVE-2014-5164: wireshark: RLC dissector crash
Status: RESOLVED DUPLICATE of bug 889854
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Chunyan Liu
Security Team bot
https://smash.suse.de/issue/104169/
maint:released:sle11-sp1:59030 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-01 07:39 UTC by Victor Pereira
Modified: 2015-02-18 23:16 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-08-01 07:39:00 UTC
CVE-2014-5164

It was reported that Wireshark's RLC dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

This is reported to affect Wireshark versions 1.10.0 to 1.10.8. It is fixed in 1.10.9.

References:
http://www.wireshark.org/security/wnpa-sec-2014-10.html
https://bugzilla.redhat.com/show_bug.cgi?id=1125763
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5164
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5164
Comment 2 Swamp Workflow Management 2014-08-01 22:00:26 UTC
bugbot adjusting priority
Comment 3 Bernhard Wiedemann 2014-08-04 03:01:36 UTC
This is an autogenerated message for OBS integration:
This bug (889900) was mentioned in
https://build.opensuse.org/request/show/243553 13.1 / wireshark
Comment 4 Chunyan Liu 2014-08-04 04:33:58 UTC
https://build.suse.de/request/show/42102 SLE-12 / wireshark

*** This bug has been marked as a duplicate of bug 889854 ***
Comment 5 Swamp Workflow Management 2014-08-20 07:04:41 UTC
openSUSE-SU-2014:1038-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 889899,889900,889901,889906
CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165
Sources used:
openSUSE 13.1 (src):    wireshark-1.10.9-20.1
Comment 6 Swamp Workflow Management 2014-09-26 22:05:01 UTC
SUSE-SU-2014:1221-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 889854,889899,889900,889901,889906,897055
CVE References: CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Server 11 SP3 (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    wireshark-1.10.10-0.2.1