Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

openSUSE: 2020:1878-1 Moderate: Wireshark Dissector Crash Fixes

opensuse
Calendar Grey November 8, 2020
Dist Opensuse Esm H88
Resolutions for various Wireshark challenges in the openSUSE Security Update: Announcement ID openSUSE-SU-2020:1878-1.
An update that fixes four vulnerabilities is now available.

Description

This update for wireshark fixes the following issues:

- Update to wireshark 3.2.7:

* CVE-2020-25863: MIME Multipart dissector crash (bsc#1176908)

* CVE-2020-25862: TCP dissector crash (bsc#1176909)

* CVE-2020-25866: BLIP dissector crash (bsc#1176910)

* CVE-2020-17498: Kafka dissector crash (bsc#1175204)

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1878=1

Package List

- openSUSE Leap 15.1 (x86_64):

libwireshark13-3.2.7-lp151.2.15.1

libwireshark13-debuginfo-3.2.7-lp151.2.15.1

libwiretap10-3.2.7-lp151.2.15.1

libwiretap10-debuginfo-3.2.7-lp151.2.15.1

libwsutil11-3.2.7-lp151.2.15.1

libwsutil11-debuginfo-3.2.7-lp151.2.15.1

wireshark-3.2.7-lp151.2.15.1

wireshark-debuginfo-3.2.7-lp151.2.15.1

wireshark-debugsource-3.2.7-lp151.2.15.1

wireshark-devel-3.2.7-lp151.2.15.1

wireshark-ui-qt-3.2.7-lp151.2.15.1

wireshark-ui-qt-debuginfo-3.2.7-lp151.2.15.1

References

https://www.suse.com/security/cve/CVE-2020-17498.html

https://www.suse.com/security/cve/CVE-2020-25862.html

https://www.suse.com/security/cve/CVE-2020-25863.html

https://www.suse.com/security/cve/CVE-2020-25866.html

https://bugzilla.suse.com/1175204

https://bugzilla.suse.com/1176908

https://bugzilla.suse.com/1176909

https://bugzilla.suse.com/1176910

--

Announcement ID: openSUSE-SU-2020:1878-1
Rating: moderate
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here