Updated wireshark package fix security vulnerabilities
Publication date: 12 Aug 2014Modification date: 12 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-5161 , CVE-2014-5162 , CVE-2014-5163 , CVE-2014-5164 , CVE-2014-5165
Description
The Catapult DCT2000 and IrDA dissectors could underrun a buffer (CVE-2014-5161, CVE-2014-5162). The GSM Management dissector could crash (CVE-2014-5163). The RLC dissector could crash (CVE-2014-5164). The ASN.1 BER dissector could crash (CVE-2014-5165). The wireshark package has been updated to version 1.10.9 to fix these issues and other bugs.
References
- https://bugs.mageia.org/show_bug.cgi?id=13839
- https://www.wireshark.org/security/wnpa-sec-2014-08.html
- https://www.wireshark.org/security/wnpa-sec-2014-09.html
- https://www.wireshark.org/security/wnpa-sec-2014-10.html
- https://www.wireshark.org/security/wnpa-sec-2014-11.html
- http://www.wireshark.org/docs/relnotes/wireshark-1.10.9.html
- http://www.wireshark.org/news/20140731.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5161
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5162
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5163
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5164
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5165
SRPMS
3/core
- wireshark-1.10.9-1.mga3
4/core
- wireshark-1.10.9-1.mga4