rpm package
opensuse/wireshark&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.2
Vulnerabilities (27)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-25863 | — | < 3.2.7-lp152.2.6.1 | 3.2.7-lp152.2.6.1 | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts. | ||
| CVE-2020-25866 | — | < 3.2.7-lp152.2.6.1 | 3.2.7-lp152.2.6.1 | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rej | ||
| CVE-2020-25862 | — | < 3.2.7-lp152.2.6.1 | 3.2.7-lp152.2.6.1 | Oct 6, 2020 | In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. | ||
| CVE-2020-17498 | — | < 3.2.7-lp152.2.6.1 | 3.2.7-lp152.2.6.1 | Aug 13, 2020 | In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression. | ||
| CVE-2020-15466 | — | < 3.2.5-lp152.2.3.1 | 3.2.5-lp152.2.3.1 | Jul 5, 2020 | In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations. | ||
| CVE-2020-13164 | — | < 3.2.5-lp152.2.3.1 | 3.2.5-lp152.2.3.1 | May 19, 2020 | In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem. | ||
| CVE-2020-11647 | — | < 3.2.5-lp152.2.3.1 | 3.2.5-lp152.2.3.1 | Apr 10, 2020 | In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion. |
- CVE-2020-25863Oct 6, 2020affected < 3.2.7-lp152.2.6.1fixed 3.2.7-lp152.2.6.1
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
- CVE-2020-25866Oct 6, 2020affected < 3.2.7-lp152.2.6.1fixed 3.2.7-lp152.2.6.1
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rej
- CVE-2020-25862Oct 6, 2020affected < 3.2.7-lp152.2.6.1fixed 3.2.7-lp152.2.6.1
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
- CVE-2020-17498Aug 13, 2020affected < 3.2.7-lp152.2.6.1fixed 3.2.7-lp152.2.6.1
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
- CVE-2020-15466Jul 5, 2020affected < 3.2.5-lp152.2.3.1fixed 3.2.5-lp152.2.3.1
In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations.
- CVE-2020-13164May 19, 2020affected < 3.2.5-lp152.2.3.1fixed 3.2.5-lp152.2.3.1
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.
- CVE-2020-11647Apr 10, 2020affected < 3.2.5-lp152.2.3.1fixed 3.2.5-lp152.2.3.1
In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.
Page 2 of 2