rpm package
suse/wireshark&distro=SUSE Linux Enterprise Server 11 SP4
pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4
Vulnerabilities (175)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2016-5357 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file. | |
| CVE-2016-5356 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file. | |
| CVE-2016-5355 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file. | |
| CVE-2016-5354 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | |
| CVE-2016-5353 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | |
| CVE-2016-5352 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | |
| CVE-2016-5351 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | |
| CVE-2016-5350 | Hig | 7.5 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 7, 2016 | epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | |
| CVE-2016-6511 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet. | |
| CVE-2016-6510 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet. | |
| CVE-2016-6509 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | |
| CVE-2016-6508 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet. | |
| CVE-2016-6507 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | |
| CVE-2016-6506 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | |
| CVE-2016-6505 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet. | |
| CVE-2016-6504 | Med | 5.9 | < 1.12.13-0.23.1 | 1.12.13-0.23.1 | Aug 6, 2016 | epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. | |
| CVE-2016-2532 | Med | 5.9 | < 1.12.11-0.18.1 | 1.12.11-0.18.1 | Feb 28, 2016 | The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application | |
| CVE-2016-2531 | Med | 5.9 | < 1.12.11-0.18.1 | 1.12.11-0.18.1 | Feb 28, 2016 | Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a d | |
| CVE-2016-2530 | Med | 5.9 | < 1.12.11-0.18.1 | 1.12.11-0.18.1 | Feb 28, 2016 | The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and | |
| CVE-2016-2523 | Med | 5.9 | < 1.12.11-0.18.1 | 1.12.11-0.18.1 | Feb 28, 2016 | The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. |
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.
- affected < 1.12.13-0.23.1fixed 1.12.13-0.23.1
epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.
- affected < 1.12.11-0.18.1fixed 1.12.11-0.18.1
The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application
- affected < 1.12.11-0.18.1fixed 1.12.11-0.18.1
Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a d
- affected < 1.12.11-0.18.1fixed 1.12.11-0.18.1
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and
- affected < 1.12.11-0.18.1fixed 1.12.11-0.18.1
The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
Page 7 of 9