wireshark-1.0.15-7.0.1.AXS3

エラータID: AXSA:2014-725:02

Release date: 
Tuesday, November 11, 2014 - 20:00
Subject: 
wireshark-1.0.15-7.0.1.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
Moderate
Description: 

Description :
Wireshark is a network traffic analyzer for Unix-ish operating systems.

This package lays base for libpcap, a packet capture and filtering
library, contains command-line utilities, contains plugins and
documentation for wireshark. A graphical user interface is packaged
separately to GTK+ package.

Security issues fixed with this release:
CVE-2014-6421
Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors.

CVE-2014-6422
The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector.

CVE-2014-6423
The tvb_raw_text_add function in epan/dissectors/packet-megaco.c in the MEGACO dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (infinite loop) via an empty line.

CVE-2014-6425
The (1) get_quoted_string and (2) get_unquoted_string functions in epan/dissectors/packet-cups.c in the CUPS dissector in Wireshark 1.12.x before 1.12.1 allow remote attackers to cause a denial of service (buffer over-read and application crash) via a CUPS packet that lacks a trailing '\0' character.

CVE-2014-6428
The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVE-2014-6429
The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not properly handle empty input data, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVE-2014-6430
The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not validate bitmask data, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVE-2014-6431
Buffer overflow in the SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers writes of uncompressed bytes beyond the end of the output buffer.

CVE-2014-6432
The SnifferDecompress function in wiretap/ngsniffer.c in the DOS Sniffer file parser in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not prevent data overwrites during copy operations, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

Solution: 

Update package.

Additional Info: 

N/A

Download: 

SRPMS
  1. wireshark-1.0.15-7.0.1.AXS3.src.rpm
    MD5: 138d7af2bc53564646eee9da2f75cc9b
    SHA-256: 8e00217b087b6d028269d52cab500f11b46e99142f9ac732c1d658a2f016abab
    Size: 12.84 MB

Asianux Server 3 for x86
  1. wireshark-1.0.15-7.0.1.AXS3.i386.rpm
    MD5: b9468d5be13529a412e81bdea0a97c23
    SHA-256: fd8775a371774099828267df99320419a96c27a581dede9483a086da3938dbe2
    Size: 10.68 MB
  2. wireshark-gnome-1.0.15-7.0.1.AXS3.i386.rpm
    MD5: 3d3a1d452afbcdc62525767f6d1828f3
    SHA-256: fba8d54c01473e87db56239c40e0ec280b9cff40ffd662e78a1372629f6f6052
    Size: 672.84 kB

Asianux Server 3 for x86_64
  1. wireshark-1.0.15-7.0.1.AXS3.x86_64.rpm
    MD5: 05595a7d3054718589e42e5875d891cb
    SHA-256: 1359125e0eaca8c3e4ba3e4d43c1deea4f373de7781f5097bb7ebbeb32bdd7c3
    Size: 11.98 MB
  2. wireshark-gnome-1.0.15-7.0.1.AXS3.x86_64.rpm
    MD5: 1c812cccac2f0351f923ad559bbadf9f
    SHA-256: bf8148833570c2f9dd41cf457b8c07a026f56ff3ca1e6473fc4a75bd38296df9
    Size: 699.42 kB