Bug 889906 - (CVE-2014-5163) VUL-0: CVE-2014-5163: wireshark: GTP and GSM Management dissectors crash
(CVE-2014-5163)
VUL-0: CVE-2014-5163: wireshark: GTP and GSM Management dissectors crash
Status: RESOLVED DUPLICATE of bug 889854
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Chunyan Liu
Security Team bot
https://smash.suse.de/issue/104170/
maint:released:sle11-sp1:59030 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-01 07:58 UTC by Victor Pereira
Modified: 2015-02-18 23:16 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2014-08-01 07:58:36 UTC
CVE-2014-5163

It was reported that Wireshark's GTP and GSM Management dissectors could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

This is reported to affect Wireshark versions 1.10.0 to 1.10.8. It is fixed in 1.10.9.

References:
http://www.wireshark.org/security/wnpa-sec-2014-09.html
https://bugzilla.redhat.com/show_bug.cgi?id=1125766
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-5163
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5163
Comment 2 Swamp Workflow Management 2014-08-01 22:00:42 UTC
bugbot adjusting priority
Comment 3 Bernhard Wiedemann 2014-08-04 03:02:51 UTC
This is an autogenerated message for OBS integration:
This bug (889906) was mentioned in
https://build.opensuse.org/request/show/243553 13.1 / wireshark
Comment 4 Chunyan Liu 2014-08-04 04:32:12 UTC
https://build.suse.de/request/show/42102 SLE-12 / wireshark

*** This bug has been marked as a duplicate of bug 889854 ***
Comment 5 Swamp Workflow Management 2014-08-20 07:05:05 UTC
openSUSE-SU-2014:1038-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 889899,889900,889901,889906
CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165
Sources used:
openSUSE 13.1 (src):    wireshark-1.10.9-20.1
Comment 6 Swamp Workflow Management 2014-09-26 22:05:22 UTC
SUSE-SU-2014:1221-1: An update that fixes 10 vulnerabilities is now available.

Category: security (important)
Bug References: 889854,889899,889900,889901,889906,897055
CVE References: CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Server 11 SP3 (src):    wireshark-1.10.10-0.2.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    wireshark-1.10.10-0.2.1
Comment 7 Swamp Workflow Management 2014-09-29 08:04:54 UTC
openSUSE-SU-2014:1249-1: An update that fixes 15 vulnerabilities is now available.

Category: security (moderate)
Bug References: 889899,889900,889901,889906,897055
CVE References: CVE-2014-5161,CVE-2014-5162,CVE-2014-5163,CVE-2014-5164,CVE-2014-5165,CVE-2014-6421,CVE-2014-6422,CVE-2014-6423,CVE-2014-6424,CVE-2014-6427,CVE-2014-6428,CVE-2014-6429,CVE-2014-6430,CVE-2014-6431,CVE-2014-6432
Sources used:
openSUSE 13.1 (src):    wireshark-1.10.10-24.1
openSUSE 12.3 (src):    wireshark-1.10.10-1.44.1