Bugzilla – Bug 905248
VUL-0: CVE-2014-8712, CVE-2014-8713: wireshark: NCP dissector crashes
Last modified: 2015-01-24 12:08:39 UTC
rh#1163582 It was reported that Wireshark's NCP dissector could crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This is reported to affect Wireshark versions 1.12.0 to 1.12.1, and 1.10.0 to 1.10.10. It is fixed in versions 1.12.2 and 1.10.11. openSUSE:13.1, openSUSE:13.2 and Factory, SLE 11 SP1, SLE 11 SP3 and SLE 12 seem to be affected References: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=10628 https://www.wireshark.org/security/wnpa-sec-2014-22.html https://bugzilla.redhat.com/show_bug.cgi?id=1163582
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2014-11-27. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/59634
Fixed for openSUSE. Maintenenace request: https://build.opensuse.org/request/show/261511
bugbot adjusting priority
openSUSE-SU-2014:1503-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 905245,905246,905247,905248 CVE References: CVE-2014-8710,CVE-2014-8711,CVE-2014-8712,CVE-2014-8713,CVE-2014-8714 Sources used: openSUSE 13.2 (src): wireshark-1.12.2-4.1 openSUSE 13.1 (src): wireshark-1.10.11-28.1 openSUSE 12.3 (src): wireshark-1.10.11-1.48.1
SUSE-SU-2014:1520-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 899303,905245,905246,905247,905248 CVE References: CVE-2014-8710,CVE-2014-8711,CVE-2014-8712,CVE-2014-8713,CVE-2014-8714 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): wireshark-1.10.11-0.2.1 SUSE Linux Enterprise Server 11 SP3 for VMware (src): wireshark-1.10.11-0.2.1 SUSE Linux Enterprise Server 11 SP3 (src): wireshark-1.10.11-0.2.1 SUSE Linux Enterprise Desktop 11 SP3 (src): wireshark-1.10.11-0.2.1
sle12 covreed by version update