From Mageia wiki
Jump to: navigation, search

MGASA-2013-0034

Date: February 6th, 2013
Affected releases: 2
Media: Core


Description:
Updated wireshark packages fix security vulnerabilities:

Infinite and large loops in the Bluetooth HCI, CSN.1, DCP-ETSI DOCSIS
CM-STAUS, IEEE 802.3 Slow Protocols, MPLS, R3, RTPS, SDP, and SIP
dissectors (wnpa-sec-2013-01).

The CLNP dissector could crash (wnpa-sec-2013-02).

The DTN dissector could crash (wnpa-sec-2013-03).

The MS-MMC dissector (and possibly others) could crash (wnpa-sec-2013-04).

The DTLS dissector could crash (wnpa-sec-2013-05).

The DCP-ETSI dissector could corrupt memory (wnpa-sec-2013-07).

The Wireshark dissection engine could crash (wnpa-sec-2013-08).

The NTLMSSP dissector could overflow a buffer (wnpa-sec-2013-09).


Updated Packages:
i586:
dumpcap-1.6.13-1.mga2.i586.rpm
libwireshark1-1.6.13-1.mga2.i586.rpm
libwireshark-devel-1.6.13-1.mga2.i586.rpm
rawshark-1.6.13-1.mga2.i586.rpm
tshark-1.6.13-1.mga2.i586.rpm
wireshark-1.6.13-1.mga2.i586.rpm
wireshark-tools-1.6.13-1.mga2.i586.rpm
wireshark-debug-1.6.13-1.mga2.i586.rpm

x86_64:
dumpcap-1.6.13-1.mga2.x86_64.rpm
lib64wireshark1-1.6.13-1.mga2.x86_64.rpm
lib64wireshark-devel-1.6.13-1.mga2.x86_64.rpm
rawshark-1.6.13-1.mga2.x86_64.rpm
tshark-1.6.13-1.mga2.x86_64.rpm
wireshark-1.6.13-1.mga2.x86_64.rpm
wireshark-tools-1.6.13-1.mga2.x86_64.rpm
wireshark-debug-1.6.13-1.mga2.x86_64.rpm

SRPMS:
wireshark-1.6.13-1.mga2.src.rpm


References:
http://www.wireshark.org/security/wnpa-sec-2013-01.html
http://www.wireshark.org/security/wnpa-sec-2013-02.html
http://www.wireshark.org/security/wnpa-sec-2013-03.html
http://www.wireshark.org/security/wnpa-sec-2013-04.html
http://www.wireshark.org/security/wnpa-sec-2013-05.html
http://www.wireshark.org/security/wnpa-sec-2013-07.html
http://www.wireshark.org/security/wnpa-sec-2013-08.html
http://www.wireshark.org/security/wnpa-sec-2013-09.html
http://www.wireshark.org/docs/relnotes/wireshark-1.6.13.html
http://www.wireshark.org/news/20130129.html
https://bugs.mageia.org/show_bug.cgi?id=8897