Bug 769578 (CVE-2012-3825) - VUl-0: CVE-2012-3825,CVE-2012-3826: wireshark: Multiple integer overflows in Wireshark
Summary: VUl-0: CVE-2012-3825,CVE-2012-3826: wireshark: Multiple integer overflows in ...
Status: RESOLVED DUPLICATE of bug 763855
Alias: CVE-2012-3825
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-07-02 08:27 UTC by Sebastian Krahmer
Modified: 2020-04-03 13:43 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2012-07-02 08:27:03 UTC
via CVE script:


Name: CVE-2012-3825

Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers
+to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bluetooth HCI
+dissectors, a different vulnerability than CVE-2012-2392.



Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7122
Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7121
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2012-08.html

======================================================
Name: CVE-2012-3826

Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers
+to cause a denial of service (loop) via vectors related to the R3 dissector, a different vulnerability
+than CVE-2012-2392.



Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7125
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2012-08.html
Comment 1 Swamp Workflow Management 2012-07-02 22:00:16 UTC
bugbot adjusting priority
Comment 2 Bamvor Jian Zhang 2012-07-03 06:54:00 UTC
Duplication of bug #763855.
Comment 3 Sebastian Krahmer 2012-07-03 06:59:17 UTC
I dont think its a dup, as it clearly states that its different
from CVE-2012-2392, which is #763855.
Comment 4 Bamvor Jian Zhang 2012-07-03 07:24:52 UTC
(In reply to comment #3)
> I dont think its a dup, as it clearly states that its different
> from CVE-2012-2392, which is #763855.

Sorry for misunderstanding. 
Although CVE-2012-3825 is different from CVE-2012-2392, they both point to the same wireshark link(http://www.wireshark.org/security/wnpa-sec-2012-08.html). 
Meanwhile, all the bugs[1][2][3] in CVE-2012-3825 already fixed in bug #763855 for all the sle wireshark maintenance version. 
So, there is no more work for me, I guess.

[1] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7122
[2] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7121
[3] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7125
Comment 5 Sebastian Krahmer 2012-07-03 08:26:45 UTC
Ans what about CVE-2012-3826?
Comment 6 Bamvor Jian Zhang 2012-07-03 08:40:42 UTC
(In reply to comment #5)
> Ans what about CVE-2012-3826?

CVE-2012-3826 include one bug [1] which is also fixed in bng #763855. 

[1] https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=7125
Comment 7 Sebastian Krahmer 2012-07-03 08:44:11 UTC
Thanks :)

*** This bug has been marked as a duplicate of bug 763855 ***