VYPR

rpm package

suse/wireshark&distro=SUSE Linux Enterprise Server 12 SP1

pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1

Vulnerabilities (70)

  • CVE-2016-7178MedSep 9, 2016
    affected < 2.2.6-44.3fixed 2.2.6-44.3

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and application crash) via a crafted pack

  • CVE-2016-7177MedSep 9, 2016
    affected < 2.2.6-44.3fixed 2.2.6-44.3

    epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

  • CVE-2016-7176MedSep 9, 2016
    affected < 2.2.6-44.3fixed 2.2.6-44.3

    epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via a crafted packet.

  • CVE-2016-7175MedSep 9, 2016
    affected < 2.2.6-44.3fixed 2.2.6-44.3

    epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

  • CVE-2016-5359MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.

  • CVE-2016-5358MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5357MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5356MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5355MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

  • CVE-2016-5354MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5353MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5352MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5351MedAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-5350HigAug 7, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

  • CVE-2016-6511MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet.

  • CVE-2016-6510MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

  • CVE-2016-6509MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

  • CVE-2016-6508MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.

  • CVE-2016-6507MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

  • CVE-2016-6506MedAug 6, 2016
    affected < 1.12.13-31.1fixed 1.12.13-31.1

    epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.