Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2020:3376-1 Moderate: Wireshark Memory Allocation Problems

suse
Calendar Grey November 19, 2020
Dist Suse Esm H88
The update from SUSE for tcpdump resolves significant buffer overflows related to packet analysis failures and infinite recursion.
An update that fixes two vulnerabilities is now available

Summary

This update for wireshark fixes the following issues: - wireshark was updated to 3.2.8: - CVE-2020-26575: Fixed an issue where FBZERO dissector was entering in infinite loop (bsc#1177406) - CVE-2020-28030: Fixed an issue where GQUIC dissector was crashing (bsc#1178291) * Infinite memory allocation while parsing this tcp packet Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-3376=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP1:

References

#1177406 #1178291

Cross- CVE-2020-26575 CVE-2020-28030

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

SUSE Linux Enterprise Module for Desktop Applications 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2020-26575.html

https://www.suse.com/security/cve/CVE-2020-28030.html

https://bugzilla.suse.com/1177406

https://bugzilla.suse.com/1178291

Announcement ID: SUSE-SU-2020:3376-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here