Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2014:1221-1 Critical: Wireshark Stability and Crash Issues

suse
Calendar Grey September 27, 2014
Scroller Suse
SUSE security update for tcpdump resolves a series of vulnerabilities and operational glitches. Critical patch deployed alongside version enhancement.
An update that fixes 10 vulnerabilities is now available

Summary

The wireshark package was upgraded to 1.10.10 from 1.8.x as 1.8 was discontinued. This update fixes vulnerabilities that could allow an attacker to crash Wireshark or make it become unresponsive by sending specific packets onto the network or have them loaded via a capture file while the dissectors are running. It also contains a number of other bug fixes. * RTP dissector crash. (wnpa-sec-2014-12 CVE-2014-6421 CVE-2014-6422) * MEGACO dissector infinite loop. (wnpa-sec-2014-13 CVE-2014-6423) * Netflow dissector crash. (wnpa-sec-2014-14 CVE-2014-6424) * RTSP dissector crash. (wnpa-sec-2014-17 CVE-2014-6427) * SES dissector crash. (wnpa-sec-2014-18 CVE-2014-6428) * Sniffer file parser crash. (wnpa-sec-2014-19 CVE-2014-6429 CVE-2014-6430 CVE-2014-6431 CVE-2014-6432)

References

#889854 #889899 #889900 #889901 #889906 #897055

Cross- CVE-2014-6421 CVE-2014-6422 CVE-2014-6423

CVE-2014-6424 CVE-2014-6427 CVE-2014-6428

CVE-2014-6429 CVE-2014-6430 CVE-2014-6431

CVE-2014-6432

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-6421.html

https://www.suse.com/security/cve/CVE-2014-6422.html

https://www.suse.com/security/cve/CVE-2014-6423.html

https://www.suse.com/security/cve/CVE-2014-6424.html

https://www.suse.com/security/cve/CVE-2014-6427.html

https://www.suse.com/security/cve/CVE-2014-6428.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1221-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.