Advisories ยป MGASA-2014-0326

Updated wireshark package fix security vulnerabilities

Publication date: 12 Aug 2014
Modification date: 12 Aug 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-5161 , CVE-2014-5162 , CVE-2014-5163 , CVE-2014-5164 , CVE-2014-5165

Description

The Catapult DCT2000 and IrDA dissectors could underrun a buffer
(CVE-2014-5161, CVE-2014-5162).

The GSM Management dissector could crash (CVE-2014-5163).

The RLC dissector could crash (CVE-2014-5164).

The ASN.1 BER dissector could crash (CVE-2014-5165).

The wireshark package has been updated to version 1.10.9 to fix these issues
and other bugs.
                

References

SRPMS

3/core

4/core