rpm package
opensuse/wireshark&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweed
Vulnerabilities (553)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2014-6425 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 20, 2014 | The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a tra | ||
| CVE-2014-6424 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 20, 2014 | The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized | ||
| CVE-2014-6423 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 20, 2014 | The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line. | ||
| CVE-2014-5165 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 1, 2014 | The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application cras | ||
| CVE-2014-5164 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 1, 2014 | The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (application crash) via a crafted pa | ||
| CVE-2014-5163 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 1, 2014 | The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial o | ||
| CVE-2014-5162 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 1, 2014 | The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buffer underflow and application c | ||
| CVE-2014-5161 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 1, 2014 | The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet. | ||
| CVE-2014-4020 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 18, 2014 | The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial o | ||
| CVE-2014-2907 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Apr 24, 2014 | The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2014-2299 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 11, 2014 | Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data. | ||
| CVE-2014-2283 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 11, 2014 | epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Rad | ||
| CVE-2014-2282 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 11, 2014 | The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet. | ||
| CVE-2014-2281 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 11, 2014 | The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and applicat | ||
| CVE-2013-7114 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Dec 19, 2013 | Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name | ||
| CVE-2013-7113 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Dec 19, 2013 | epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-7112 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Dec 19, 2013 | The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | ||
| CVE-2013-6340 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 4, 2013 | epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-6339 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 4, 2013 | The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet. | ||
| CVE-2013-6338 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 4, 2013 | The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a craft |
- CVE-2014-6425Sep 20, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a tra
- CVE-2014-6424Sep 20, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized
- CVE-2014-6423Sep 20, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line.
- CVE-2014-5165Aug 1, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application cras
- CVE-2014-5164Aug 1, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure member only after this member is used, which allows remote attackers to cause a denial of service (application crash) via a crafted pa
- CVE-2014-5163Aug 1, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial o
- CVE-2014-5162Aug 1, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote attackers to cause a denial of service (off-by-one buffer underflow and application c
- CVE-2014-5161Aug 1, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.
- CVE-2014-4020Jun 18, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial o
- CVE-2014-2907Apr 24, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2014-2299Mar 11, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.
- CVE-2014-2283Mar 11, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Rad
- CVE-2014-2282Mar 11, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.
- CVE-2014-2281Mar 11, 2014affected < 2.2.2-1.1fixed 2.2.2-1.1
The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and applicat
- CVE-2013-7114Dec 19, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name
- CVE-2013-7113Dec 19, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-7112Dec 19, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- CVE-2013-6340Nov 4, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-6339Nov 4, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet.
- CVE-2013-6338Nov 4, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a craft
Page 21 of 28