rpm package
opensuse/wireshark&distro=openSUSE Leap 15.2
pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.2
Vulnerabilities (27)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-39929 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39926 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39925 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39924 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39922 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39921 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 19, 2021 | NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39928 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 18, 2021 | NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-39920 | — | < 3.4.10-lp152.2.21.1 | 3.4.10-lp152.2.21.1 | Nov 18, 2021 | NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-22235 | — | < 3.4.7-lp152.2.18.1 | 3.4.7-lp152.2.18.1 | Jul 20, 2021 | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-22207 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Apr 23, 2021 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-22191 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Mar 15, 2021 | Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file. | ||
| CVE-2021-22173 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Feb 17, 2021 | Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | ||
| CVE-2021-22174 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Feb 17, 2021 | Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file | ||
| CVE-2020-26422 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Dec 21, 2020 | Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file | ||
| CVE-2020-26418 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Dec 11, 2020 | Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | ||
| CVE-2020-26421 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Dec 11, 2020 | Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | ||
| CVE-2020-26420 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Dec 11, 2020 | Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file. | ||
| CVE-2020-26419 | — | < 3.4.5-lp152.2.12.1 | 3.4.5-lp152.2.12.1 | Dec 11, 2020 | Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file. | ||
| CVE-2020-28030 | — | < 3.2.8-lp152.2.9.1 | 3.2.8-lp152.2.9.1 | Oct 30, 2020 | In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement. | ||
| CVE-2020-26575 | — | < 3.2.8-lp152.2.9.1 | 3.2.8-lp152.2.9.1 | Oct 6, 2020 | In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement. |
- CVE-2021-39929Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39926Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- CVE-2021-39925Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39924Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39922Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39921Nov 19, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39928Nov 18, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- CVE-2021-39920Nov 18, 2021affected < 3.4.10-lp152.2.21.1fixed 3.4.10-lp152.2.21.1
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- CVE-2021-22235Jul 20, 2021affected < 3.4.7-lp152.2.18.1fixed 3.4.7-lp152.2.18.1
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
- CVE-2021-22207Apr 23, 2021affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
- CVE-2021-22191Mar 15, 2021affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
- CVE-2021-22173Feb 17, 2021affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- CVE-2021-22174Feb 17, 2021affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- CVE-2020-26422Dec 21, 2020affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
- CVE-2020-26418Dec 11, 2020affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26421Dec 11, 2020affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26420Dec 11, 2020affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- CVE-2020-26419Dec 11, 2020affected < 3.4.5-lp152.2.12.1fixed 3.4.5-lp152.2.12.1
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
- CVE-2020-28030Oct 30, 2020affected < 3.2.8-lp152.2.9.1fixed 3.2.8-lp152.2.9.1
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- CVE-2020-26575Oct 6, 2020affected < 3.2.8-lp152.2.9.1fixed 3.2.8-lp152.2.9.1
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
Page 1 of 2