MGASA-2024-0303 - Updated wireshark packages fix security vulnerability

Publication date: 16 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0303.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-8250

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16
allows denial of service via packet injection or crafted capture file.
(CVE-2024-8250)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33558
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QKFBRZUBCTYT4V2V5ONIWBIEEUYHI3HD/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8250

SRPMS:
- 9/core/wireshark-4.0.17-1.mga9

Mageia 2024-0303: wireshark Security Advisory Updates

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file

Summary

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file. (CVE-2024-8250)

References

- https://bugs.mageia.org/show_bug.cgi?id=33558

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QKFBRZUBCTYT4V2V5ONIWBIEEUYHI3HD/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8250

Resolution

MGASA-2024-0303 - Updated wireshark packages fix security vulnerability

SRPMS

- 9/core/wireshark-4.0.17-1.mga9

Severity
Publication date: 16 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0303.html
Type: security
CVE: CVE-2024-8250

Related News