rpm package
opensuse/wireshark&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweed
Vulnerabilities (553)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-6337 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 4, 2013 | Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-6336 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 4, 2013 | The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a cr | ||
| CVE-2013-5722 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-5721 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | The dissect_mq_rr function in epan/dissectors/packet-mq.c in the MQ dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not properly determine when to enter a certain loop, which allows remote attackers to cause a denial of service (application crash) via a c | ||
| CVE-2013-5720 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-5719 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | ||
| CVE-2013-5718 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application crash) via a crafted pac | ||
| CVE-2013-5717 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 16, 2013 | The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that is not properly handled by the wmem_block_alloc function in e | ||
| CVE-2013-4936 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a cra | ||
| CVE-2013-4935 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of se | ||
| CVE-2013-4934 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize certain structure members, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace | ||
| CVE-2013-4933 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file. | ||
| CVE-2013-4932 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application crash) via a crafted packet. | ||
| CVE-2013-4931 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a crafted packet that is not properly handled by the GSM RR dissector. | ||
| CVE-2013-4930 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not validate a certain length value before decrementing it, which allows remote attackers to cause a denial of service (asse | ||
| CVE-2013-4929 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | The parseFields function in epan/dissectors/packet-dis-pdus.c in the DIS dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not terminate packet-data processing after finding zero remaining bytes, which allows remote attackers to cause a denial of service (lo | ||
| CVE-2013-4928 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | Integer signedness error in the dissect_headers function in epan/dissectors/packet-btobex.c in the Bluetooth OBEX dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | ||
| CVE-2013-4927 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet. | ||
| CVE-2013-4926 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers to cause a denial of service (application crash) via a crafte | ||
| CVE-2013-4925 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 30, 2013 | Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted packet. |
- CVE-2013-6337Nov 4, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-6336Nov 4, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a cr
- CVE-2013-5722Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in the LDAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-5721Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_mq_rr function in epan/dissectors/packet-mq.c in the MQ dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not properly determine when to enter a certain loop, which allows remote attackers to cause a denial of service (application crash) via a c
- CVE-2013-5720Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Buffer overflow in the RTPS dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-5719Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-assa_r3.c in the ASSA R3 dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- CVE-2013-5718Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application crash) via a crafted pac
- CVE-2013-5717Sep 16, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that is not properly handled by the wmem_block_alloc function in e
- CVE-2013-4936Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a cra
- CVE-2013-4935Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attackers to cause a denial of se
- CVE-2013-4934Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize certain structure members, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace
- CVE-2013-4933Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted packet-trace file.
- CVE-2013-4932Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Multiple array index errors in epan/dissectors/packet-gsm_a_common.c in the GSM A Common dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allow remote attackers to cause a denial of service (application crash) via a crafted packet.
- CVE-2013-4931Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/proto.c in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop) via a crafted packet that is not properly handled by the GSM RR dissector.
- CVE-2013-4930Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not validate a certain length value before decrementing it, which allows remote attackers to cause a denial of service (asse
- CVE-2013-4929Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
The parseFields function in epan/dissectors/packet-dis-pdus.c in the DIS dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not terminate packet-data processing after finding zero remaining bytes, which allows remote attackers to cause a denial of service (lo
- CVE-2013-4928Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Integer signedness error in the dissect_headers function in epan/dissectors/packet-btobex.c in the Bluetooth OBEX dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- CVE-2013-4927Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Integer signedness error in the get_type_length function in epan/dissectors/packet-btsdp.c in the Bluetooth SDP dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet.
- CVE-2013-4926Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers to cause a denial of service (application crash) via a crafte
- CVE-2013-4925Jul 30, 2013affected < 2.2.2-1.1fixed 2.2.2-1.1
Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted packet.
Page 22 of 28