Bugzilla – Bug 912372
VUL-0: CVE-2015-0564: Wireshark: TLS/SSL decryption crash
Last modified: 2015-03-05 08:19:32 UTC
From https://www.wireshark.org/security/wnpa-sec-2015-05.html Name: TLS/SSL decryption crash Docid: wnpa-sec-2015-05 Date: January 7, 2015 Affected versions: 1.12.0 to 1.12.2, 1.10.0 to 1.10.11 (Includes previous versions) Fixed versions: 1.12.3, 1.10.12 References: CVE-2015-0564 Wireshark could underflow a buffer while decypting TLS/SSL sessions. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
This is an autogenerated message for OBS integration: This bug (912372) was mentioned in https://build.opensuse.org/request/show/280659 13.2+13.1 / wireshark
bugbot adjusting priority
openSUSE-SU-2015:0113-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: openSUSE 13.2 (src): wireshark-1.12.3-8.1 openSUSE 13.1 (src): wireshark-1.10.12-32.1
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-02-19. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60550
SUSE-SU-2015:0307-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): wireshark-1.10.12-4.1 SUSE Linux Enterprise Server 12 (src): wireshark-1.10.12-4.1 SUSE Linux Enterprise Desktop 12 (src): wireshark-1.10.12-4.1
released
SUSE-SU-2015:0426-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Server 11 SP3 for VMware (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Server 11 SP3 (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Desktop 11 SP3 (src): wireshark-1.10.12-0.2.1