SUSE-SU-2012:0296-2: moderate: Security update for wireshark

sle-updates at lists.suse.com sle-updates at lists.suse.com
Sun Feb 26 17:08:33 MST 2012


   SUSE Security Update: Security update for wireshark
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:0296-2
Rating:             moderate
References:         #741187 #741188 #741190 
Cross-References:   CVE-2012-0041 CVE-2012-0042 CVE-2012-0043
                    CVE-2012-0066 CVE-2012-0067 CVE-2012-0068
                   
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP1
                    SUSE Linux Enterprise Server 11 SP1 for VMware
                    SUSE Linux Enterprise Server 11 SP1
                    SUSE Linux Enterprise Desktop 11 SP1
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available. It
   includes one version update.

Description:


   This version upgrade of wireshark to 1.4.11 fixes the
   following security  issues:

   * CVE-2012-0043: RLC dissector buffer overflow
   * CVE-2012-0041: multiple file parser vulnerabilities
   * CVE-2012-0042: NULL pointer vulnerabilities
   * CVE-2012-0066: DoS due to too large buffer alloc
   request
   * CVE-2012-0067: DoS due to integer underflow and too
   large buffer alloc. request
   * CVE-2012-0068: memory corruption due to buffer
   underflow

   Additionally, various other non-security issues were
   resolved.

   Security Issue references:

   * CVE-2012-0041
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0041
   >
   * CVE-2012-0043
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0043
   >
   * CVE-2012-0042
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0042
   >
   * CVE-2012-0066
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0066
   >
   * CVE-2012-0067
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0067
   >
   * CVE-2012-0068
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0068
   >


Special Instructions and Notes:

   This update triggers a restart of the software management
   stack. More updates will be available for installation
   after applying this update and restarting the application.
   This update triggers a restart of the software management
   stack. More updates will be available for installation
   after applying this update and restarting the application.
   This update triggers a restart of the software management
   stack. More updates will be available for installation
   after applying this update and restarting the application.
   This update triggers a restart of the software management
   stack. More updates will be available for installation
   after applying this update and restarting the application.

Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP1:

      zypper in -t patch sdksp1-wireshark-5741

   - SUSE Linux Enterprise Server 11 SP1 for VMware:

      zypper in -t patch slessp1-wireshark-5741

   - SUSE Linux Enterprise Server 11 SP1:

      zypper in -t patch slessp1-wireshark-5741

   - SUSE Linux Enterprise Desktop 11 SP1:

      zypper in -t patch sledsp1-wireshark-5741

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.4.11]:

      wireshark-devel-1.4.11-0.2.2.1

   - SUSE Linux Enterprise Software Development Kit 11 SP1 (i586 x86_64) [New Version: 1.4.11]:

      wireshark-1.4.11-0.2.2.1

   - SUSE Linux Enterprise Server 11 SP1 for VMware (i586 x86_64) [New Version: 1.4.11]:

      wireshark-1.4.11-0.2.2.1

   - SUSE Linux Enterprise Server 11 SP1 (i586 ia64 ppc64 s390x x86_64) [New Version: 1.4.11]:

      wireshark-1.4.11-0.2.2.1

   - SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64) [New Version: 1.4.11]:

      wireshark-1.4.11-0.2.2.1


References:

   http://support.novell.com/security/cve/CVE-2012-0041.html
   http://support.novell.com/security/cve/CVE-2012-0042.html
   http://support.novell.com/security/cve/CVE-2012-0043.html
   http://support.novell.com/security/cve/CVE-2012-0066.html
   http://support.novell.com/security/cve/CVE-2012-0067.html
   http://support.novell.com/security/cve/CVE-2012-0068.html
   https://bugzilla.novell.com/741187
   https://bugzilla.novell.com/741188
   https://bugzilla.novell.com/741190
   http://download.novell.com/patch/finder/?keywords=18b5892df9e0199c97b6d5e6805fb1e9



More information about the sle-updates mailing list