rpm package
opensuse/wireshark&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweed
Vulnerabilities (553)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2011-1592 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Apr 29, 2011 | The NFS dissector in epan/dissectors/packet-nfs.c in Wireshark 1.4.x before 1.4.5 on Windows uses an incorrect integer data type during decoding of SETCLIENTID calls, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file. | ||
| CVE-2011-1591 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Apr 29, 2011 | Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file. | ||
| CVE-2011-1590 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Apr 29, 2011 | The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file. | ||
| CVE-2011-0024 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 28, 2011 | Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file. | ||
| CVE-2011-1143 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 3, 2011 | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file. | ||
| CVE-2011-1140 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 3, 2011 | Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or | ||
| CVE-2011-1139 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 3, 2011 | wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field. | ||
| CVE-2011-1138 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 3, 2011 | Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet. | ||
| CVE-2011-0713 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Mar 3, 2011 | Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long record in a Nokia DCT3 trace file. | ||
| CVE-2011-0538 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Feb 8, 2011 | Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a ma | ||
| CVE-2010-4538 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Jan 7, 2011 | Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) comp | ||
| CVE-2010-4301 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 26, 2010 | epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes. | ||
| CVE-2010-4300 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 26, 2010 | Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an | ||
| CVE-2010-3445 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Nov 26, 2010 | Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long st | ||
| CVE-2010-2993 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Aug 13, 2010 | The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors. | ||
| CVE-2010-1455 | — | < 2.2.2-1.1 | 2.2.2-1.1 | May 12, 2010 | The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file. | ||
| CVE-2009-3243 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 18, 2009 | Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations. | ||
| CVE-2009-3242 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 18, 2009 | Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure. | ||
| CVE-2009-3241 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Sep 18, 2009 | Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets. | ||
| CVE-2009-1269 | — | < 2.2.2-1.1 | 2.2.2-1.1 | Apr 13, 2009 | Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file. |
- CVE-2011-1592Apr 29, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The NFS dissector in epan/dissectors/packet-nfs.c in Wireshark 1.4.x before 1.4.5 on Windows uses an incorrect integer data type during decoding of SETCLIENTID calls, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
- CVE-2011-1591Apr 29, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file.
- CVE-2011-1590Apr 29, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
- CVE-2011-0024Mar 28, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
- CVE-2011-1143Mar 3, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.
- CVE-2011-1140Mar 3, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or
- CVE-2011-1139Mar 3, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field.
- CVE-2011-1138Mar 3, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
- CVE-2011-0713Mar 3, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long record in a Nokia DCT3 trace file.
- CVE-2011-0538Feb 8, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a ma
- CVE-2010-4538Jan 7, 2011affected < 2.2.2-1.1fixed 2.2.2-1.1
Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) comp
- CVE-2010-4301Nov 26, 2010affected < 2.2.2-1.1fixed 2.2.2-1.1
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes.
- CVE-2010-4300Nov 26, 2010affected < 2.2.2-1.1fixed 2.2.2-1.1
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an
- CVE-2010-3445Nov 26, 2010affected < 2.2.2-1.1fixed 2.2.2-1.1
Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long st
- CVE-2010-2993Aug 13, 2010affected < 2.2.2-1.1fixed 2.2.2-1.1
The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
- CVE-2010-1455May 12, 2010affected < 2.2.2-1.1fixed 2.2.2-1.1
The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.
- CVE-2009-3243Sep 18, 2009affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.
- CVE-2009-3242Sep 18, 2009affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.
- CVE-2009-3241Sep 18, 2009affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.
- CVE-2009-1269Apr 13, 2009affected < 2.2.2-1.1fixed 2.2.2-1.1
Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.
Page 27 of 28