rpm package
opensuse/wireshark&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweed
Vulnerabilities (553)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2012-4289 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 16, 2012 | epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries. | ||
| CVE-2012-4288 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 16, 2012 | Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value | ||
| CVE-2012-4287 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 16, 2012 | epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length. | ||
| CVE-2012-4286 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 16, 2012 | The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted pcap-ng file. | ||
| CVE-2012-4285 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 16, 2012 | The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-lengt | ||
| CVE-2012-4049 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 24, 2012 | epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet. | ||
| CVE-2012-4048 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 24, 2012 | The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump. | ||
| CVE-2012-2394 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 30, 2012 | Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a (1) ICMP or (2) ICMPv6 Echo Reques | ||
| CVE-2012-2393 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 30, 2012 | epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that | ||
| CVE-2012-2392 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 30, 2012 | Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors. | ||
| CVE-2011-3483 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 20, 2011 | Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability." | ||
| CVE-2011-3360 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 20, 2011 | Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory. | ||
| CVE-2011-3266 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 24, 2011 | The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in | ||
| CVE-2011-2698 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 23, 2011 | Off-by-one error in the elem_cell_id_aux function in epan/dissectors/packet-ansi_a.c in the ANSI MAP dissector in Wireshark 1.4.x before 1.4.8 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (infinite loop) via an invalid packet. | ||
| CVE-2011-2597 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jul 7, 2011 | The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets. | ||
| CVE-2011-2175 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 6, 2011 | Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read. | ||
| CVE-2011-2174 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 6, 2011 | Double free vulnerability in the tvb_uncompress function in epan/tvbuff.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a packet with malformed data that uses zlib compression. | ||
| CVE-2011-1959 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 6, 2011 | The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 does not properly handle certain virtualizable buffers, which allows remote attackers to cause a denial of service (application crash) via a large length value in a snoop file that | ||
| CVE-2011-1958 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 6, 2011 | Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Diameter dictionary file. | ||
| CVE-2011-1957 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jun 6, 2011 | The dissect_dcm_main function in epan/dissectors/packet-dcm.c in the DICOM dissector in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (infinite loop) via an invalid PDU length. |
- CVE-2012-4289Aug 16, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.
- CVE-2012-4288Aug 16, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop or application crash) via a large value
- CVE-2012-4287Aug 16, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-mongo.c in the MongoDB dissector in Wireshark 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a small value for a BSON document length.
- CVE-2012-4286Aug 16, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
The pcapng_read_packet_block function in wiretap/pcapng.c in the pcap-ng file parser in Wireshark 1.8.x before 1.8.2 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted pcap-ng file.
- CVE-2012-4285Aug 16, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-lengt
- CVE-2012-4049Jul 24, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet.
- CVE-2012-4048Jul 24, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump.
- CVE-2012-2394Jun 30, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a (1) ICMP or (2) ICMPv6 Echo Reques
- CVE-2012-2393Jun 30, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote attackers to cause a denial of service (application crash) via a crafted packet that
- CVE-2012-2392Jun 30, 2012affected < 2.2.2-1.1fixed 2.2.2-1.1
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 802.3, and (5) LTP dissectors.
- CVE-2011-3483Sep 20, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."
- CVE-2011-3360Sep 20, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.
- CVE-2011-3266Aug 24, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in
- CVE-2011-2698Aug 23, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Off-by-one error in the elem_cell_id_aux function in epan/dissectors/packet-ansi_a.c in the ANSI MAP dissector in Wireshark 1.4.x before 1.4.8 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (infinite loop) via an invalid packet.
- CVE-2011-2597Jul 7, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.
- CVE-2011-2175Jun 6, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read.
- CVE-2011-2174Jun 6, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Double free vulnerability in the tvb_uncompress function in epan/tvbuff.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a packet with malformed data that uses zlib compression.
- CVE-2011-1959Jun 6, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 does not properly handle certain virtualizable buffers, which allows remote attackers to cause a denial of service (application crash) via a large length value in a snoop file that
- CVE-2011-1958Jun 6, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Diameter dictionary file.
- CVE-2011-1957Jun 6, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The dissect_dcm_main function in epan/dissectors/packet-dcm.c in the DICOM dissector in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (infinite loop) via an invalid PDU length.
Page 26 of 28