rpm package
opensuse/wireshark&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Tumbleweed
Vulnerabilities (581)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-39929 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39926 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39925 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39924 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39922 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39921 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 19, 2021 | NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39928 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 18, 2021 | NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-39920 | Hig | 7.5 | < 3.4.10-1.1 | 3.4.10-1.1 | Nov 18, 2021 | NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-22235 | Hig | 7.5 | < 3.4.8-1.2 | 3.4.8-1.2 | Jul 20, 2021 | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-22207 | Med | 5.5 | < 3.4.8-1.2 | 3.4.8-1.2 | Apr 23, 2021 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-22191 | Med | 6.3 | < 3.4.8-1.2 | 3.4.8-1.2 | Mar 15, 2021 | Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. | |
| CVE-2021-22174 | Low | 3.7 | < 3.4.8-1.2 | 3.4.8-1.2 | Feb 17, 2021 | Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |
| CVE-2021-22173 | Low | 3.7 | < 3.4.8-1.2 | 3.4.8-1.2 | Feb 17, 2021 | Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | |
| CVE-2020-26422 | Low | 3.7 | < 3.4.8-1.2 | 3.4.8-1.2 | Dec 21, 2020 | Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file | |
| CVE-2020-26421 | Med | 4.2 | < 3.4.8-1.2 | 3.4.8-1.2 | Dec 11, 2020 | Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | |
| CVE-2020-26420 | Low | 3.1 | < 3.4.8-1.2 | 3.4.8-1.2 | Dec 11, 2020 | Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | |
| CVE-2020-26419 | Low | 3.1 | < 3.4.8-1.2 | 3.4.8-1.2 | Dec 11, 2020 | Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. | |
| CVE-2020-26418 | Low | 3.1 | < 3.4.8-1.2 | 3.4.8-1.2 | Dec 11, 2020 | Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | |
| CVE-2020-28030 | Hig | 7.5 | < 3.4.8-1.2 | 3.4.8-1.2 | Nov 2, 2020 | In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement. | |
| CVE-2020-26575 | Hig | 7.5 | < 3.4.8-1.2 | 3.4.8-1.2 | Oct 6, 2020 | In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement. |
- affected < 3.4.10-1.1fixed 3.4.10-1.1
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- affected < 3.4.10-1.1fixed 3.4.10-1.1
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- affected < 3.4.8-1.2fixed 3.4.8-1.2
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
Page 9 of 30