Bug 905248 - (CVE-2014-8712) VUL-0: CVE-2014-8712, CVE-2014-8713: wireshark: NCP dissector crashes
(CVE-2014-8712)
VUL-0: CVE-2014-8712, CVE-2014-8713: wireshark: NCP dissector crashes
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/110704/
maint:released:sle11-sp3:59670 maint...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-11-13 08:40 UTC by Johannes Segitz
Modified: 2015-01-24 12:08 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-11-13 08:40:11 UTC
rh#1163582

It was reported that Wireshark's NCP dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

This is reported to affect Wireshark versions 1.12.0 to 1.12.1, and 1.10.0 to 1.10.10. It is fixed in versions 1.12.2 and 1.10.11.

openSUSE:13.1, openSUSE:13.2 and Factory, SLE 11 SP1,  SLE 11 SP3 and SLE 12 seem to be affected

References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10628
https://www.wireshark.org/security/wnpa-sec-2014-22.html
https://bugzilla.redhat.com/show_bug.cgi?id=1163582
Comment 1 Swamp Workflow Management 2014-11-13 09:23:51 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-11-27.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/59634
Comment 2 Andreas Stieger 2014-11-13 21:39:32 UTC
Fixed for openSUSE.
Maintenenace request: https://build.opensuse.org/request/show/261511
Comment 3 Swamp Workflow Management 2014-11-13 23:00:40 UTC
bugbot adjusting priority
Comment 5 Swamp Workflow Management 2014-11-26 09:05:46 UTC
openSUSE-SU-2014:1503-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 905245,905246,905247,905248
CVE References: CVE-2014-8710,CVE-2014-8711,CVE-2014-8712,CVE-2014-8713,CVE-2014-8714
Sources used:
openSUSE 13.2 (src):    wireshark-1.12.2-4.1
openSUSE 13.1 (src):    wireshark-1.10.11-28.1
openSUSE 12.3 (src):    wireshark-1.10.11-1.48.1
Comment 6 Swamp Workflow Management 2014-11-28 06:05:27 UTC
SUSE-SU-2014:1520-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 899303,905245,905246,905247,905248
CVE References: CVE-2014-8710,CVE-2014-8711,CVE-2014-8712,CVE-2014-8713,CVE-2014-8714
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    wireshark-1.10.11-0.2.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    wireshark-1.10.11-0.2.1
SUSE Linux Enterprise Server 11 SP3 (src):    wireshark-1.10.11-0.2.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    wireshark-1.10.11-0.2.1
Comment 7 Marcus Meissner 2015-01-24 12:08:39 UTC
sle12 covreed by version update