Bugzilla – Bug 889901
VUL-0: CVE-2014-5161 CVE-2014-5162: wireshark: Catapult DCT2000 and IrDA dissectors buffer underrun
Last modified: 2015-02-18 23:16:28 UTC
CVE-2014-5161 CVE-2014-5162 It was reported that Wireshark's Catapult DCT2000 and IrDA dissectors could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This is reported to affect Wireshark versions 1.10.0 to 1.10.8. It is fixed in 1.10.9. References: http://www.wireshark.org/security/wnpa-sec-2014-08.html https://bugzilla.redhat.com/show_bug.cgi?id=1125767 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5162 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5161 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5162 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5161
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (889901) was mentioned in https://build.opensuse.org/request/show/243553 13.1 / wireshark
https://build.suse.de/request/show/42102 SLE-12 / wireshark *** This bug has been marked as a duplicate of bug 889854 ***
openSUSE-SU-2014:1038-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 889899,889900,889901,889906 CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165 Sources used: openSUSE 13.1 (src): wireshark-1.10.9-20.1
SUSE-SU-2014:1221-1: An update that fixes 10 vulnerabilities is now available. Category: security (important) Bug References: 889854,889899,889900,889901,889906,897055 CVE References: CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): wireshark-1.10.10-0.2.1 SUSE Linux Enterprise Server 11 SP3 for VMware (src): wireshark-1.10.10-0.2.1 SUSE Linux Enterprise Server 11 SP3 (src): wireshark-1.10.10-0.2.1 SUSE Linux Enterprise Desktop 11 SP3 (src): wireshark-1.10.10-0.2.1
openSUSE-SU-2014:1249-1: An update that fixes 15 vulnerabilities is now available. Category: security (moderate) Bug References: 889899,889900,889901,889906,897055 CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165,CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432 Sources used: openSUSE 13.1 (src): wireshark-1.10.10-24.1 openSUSE 12.3 (src): wireshark-1.10.10-1.44.1