SUSE-SU-2014:1221-1: important: Security update for wireshark

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Fri Sep 26 16:04:30 MDT 2014


   SUSE Security Update: Security update for wireshark
______________________________________________________________________________

Announcement ID:    SUSE-SU-2014:1221-1
Rating:             important
References:         #889854 #889899 #889900 #889901 #889906 #897055 
                    
Cross-References:   CVE-2014-6421 CVE-2014-6422 CVE-2014-6423
                    CVE-2014-6424 CVE-2014-6427 CVE-2014-6428
                    CVE-2014-6429 CVE-2014-6430 CVE-2014-6431
                    CVE-2014-6432
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP3
                    SUSE Linux Enterprise Server 11 SP3 for VMware
                    SUSE Linux Enterprise Server 11 SP3
                    SUSE Linux Enterprise Desktop 11 SP3
______________________________________________________________________________

   An update that fixes 10 vulnerabilities is now available.
   It includes one version update.

Description:


   The wireshark package was upgraded to 1.10.10 from 1.8.x as 1.8 was
   discontinued.

   This update fixes vulnerabilities that could allow an attacker to crash
   Wireshark or make it become unresponsive by sending specific packets onto
   the network or have them loaded via a capture file while the dissectors
   are running. It also contains a number of other bug fixes.

       * RTP dissector crash. (wnpa-sec-2014-12 CVE-2014-6421 CVE-2014-6422)
       * MEGACO dissector infinite loop. (wnpa-sec-2014-13 CVE-2014-6423)
       * Netflow dissector crash. (wnpa-sec-2014-14 CVE-2014-6424)
       * RTSP dissector crash. (wnpa-sec-2014-17 CVE-2014-6427)
       * SES dissector crash. (wnpa-sec-2014-18 CVE-2014-6428)
       * Sniffer file parser crash. (wnpa-sec-2014-19 CVE-2014-6429
         CVE-2014-6430 CVE-2014-6431 CVE-2014-6432)
       * The Catapult DCT2000 and IrDA dissectors could underrun a buffer.
         (wnpa-sec-2014-08 CVE-2014-5161 CVE-2014-5162, bnc#889901)
       * The GSM Management dissector could crash. (wnpa-sec-2014-09
         CVE-2014-5163, bnc#889906)
       * The RLC dissector could crash. (wnpa-sec-2014-10 CVE-2014-5164,
         bnc#889900)
       * The ASN.1 BER dissector could crash. (wnpa-sec-2014-11
         CVE-2014-5165, bnc#889899)

   Further bug fixes as listed in:
   https://www.wireshark.org/docs/relnotes/wireshark-1.10.10.html
   <https://www.wireshark.org/docs/relnotes/wireshark-1.10.10.html> and
   https://www.wireshark.org/docs/relnotes/wireshark-1.10.9.html
   <https://www.wireshark.org/docs/relnotes/wireshark-1.10.9.html> .

   Security Issues:

       * CVE-2014-5161
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5161>
       * CVE-2014-5162
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5162>
       * CVE-2014-5163
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5163>
       * CVE-2014-5164
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5164>
       * CVE-2014-5165
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5165>
       * CVE-2014-6421
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6421>
       * CVE-2014-6422
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6422>
       * CVE-2014-6423
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6423>
       * CVE-2014-6424
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6424>
       * CVE-2014-6427
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6427>
       * CVE-2014-6428
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6428>
       * CVE-2014-6429
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6429>
       * CVE-2014-6430
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6430>
       * CVE-2014-6431
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6431>
       * CVE-2014-6432
         <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6432>


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP3:

      zypper in -t patch sdksp3-wireshark-9745

   - SUSE Linux Enterprise Server 11 SP3 for VMware:

      zypper in -t patch slessp3-wireshark-9745

   - SUSE Linux Enterprise Server 11 SP3:

      zypper in -t patch slessp3-wireshark-9745

   - SUSE Linux Enterprise Desktop 11 SP3:

      zypper in -t patch sledsp3-wireshark-9745

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.10.10]:

      wireshark-devel-1.10.10-0.2.1

   - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 x86_64) [New Version: 1.10.10]:

      wireshark-1.10.10-0.2.1

   - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64) [New Version: 1.10.10]:

      wireshark-1.10.10-0.2.1

   - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.10.10]:

      wireshark-1.10.10-0.2.1

   - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 1.10.10]:

      wireshark-1.10.10-0.2.1


References:

   http://support.novell.com/security/cve/CVE-2014-6421.html
   http://support.novell.com/security/cve/CVE-2014-6422.html
   http://support.novell.com/security/cve/CVE-2014-6423.html
   http://support.novell.com/security/cve/CVE-2014-6424.html
   http://support.novell.com/security/cve/CVE-2014-6427.html
   http://support.novell.com/security/cve/CVE-2014-6428.html
   http://support.novell.com/security/cve/CVE-2014-6429.html
   http://support.novell.com/security/cve/CVE-2014-6430.html
   http://support.novell.com/security/cve/CVE-2014-6431.html
   http://support.novell.com/security/cve/CVE-2014-6432.html
   https://bugzilla.suse.com/889854
   https://bugzilla.suse.com/889899
   https://bugzilla.suse.com/889900
   https://bugzilla.suse.com/889901
   https://bugzilla.suse.com/889906
   https://bugzilla.suse.com/897055
   http://download.suse.com/patch/finder/?keywords=25a84c702b8b4fdaea63a171632f5a93



More information about the sle-security-updates mailing list