Description: | Summary: The remote host is missing an update for the 'wireshark' package(s) announced via the SUSE-SU-2013:0714-1 advisory.
Vulnerability Insight: wireshark has been updated to 1.8.6 which fixes bugs and security issues:
Vulnerabilities fixed:
* The TCP dissector could crash. wnpa-sec-2013-10 CVE-2013-2475 * The HART/IP dissectory could go into an infinite loop. wnpa-sec-2013-11 CVE-2013-2476 * The CSN.1 dissector could crash. wnpa-sec-2013-12 CVE-2013-2477 * The MS-MMS dissector could crash. wnpa-sec-2013-13 CVE-2013-2478 * The MPLS Echo dissector could go into an infinite loop. wnpa-sec-2013-14 CVE-2013-2479 * The RTPS and RTPS2 dissectors could crash. wnpa-sec-2013-15 CVE-2013-2480 * The Mount dissector could crash. wnpa-sec-2013-16 CVE-2013-2481 * The AMPQ dissector could go into an infinite loop. wnpa-sec-2013-17 CVE-2013-2482 * The ACN dissector could attempt to divide by zero. wnpa-sec-2013-18 CVE-2013-2483 * The CIMD dissector could crash. wnpa-sec-2013-19 CVE-2013-2484 * The FCSP dissector could go into an infinite loop. wnpa-sec-2013-20 CVE-2013-2485 * The RELOAD dissector could go into an infinite loop. wnpa-sec-2013-21 CVE-2013-2486 CVE-2013-2487 * The DTLS dissector could crash. wnpa-sec-2013-22 CVE-2013-2488
More information about further bug fixes and updated protocol support are listed here: [link moved to references] >
Security Issue references:
* CVE-2013-2475 > * CVE-2013-2476 > * CVE-2013-2477 > * CVE-2013-2478 > * CVE-2013-2479 > * CVE-2013-2480 > * CVE-2013-2481 > * CVE-2013-2482 > * CVE-2013-2483 > * CVE-2013-2484 > * CVE-2013-2485 > * CVE-2013-2486 > * CVE-2013-2487 > * CVE-2013-2488 >
Affected Software/OS: 'wireshark' package(s) on SUSE Linux Enterprise Desktop 10-SP4, SUSE Linux Enterprise Desktop 11-SP2, SUSE Linux Enterprise Server 10-SP4, SUSE Linux Enterprise Server 11-SP2, SUSE Linux Enterprise Software Development Kit 11-SP2.
Solution: Please install the updated package(s).
CVSS Score: 7.8
CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C
|