Bugzilla – Bug 912365
VUL-0: CVE-2015-0559, CVE-2015-0560: Wireshark: WCCP dissector crash
Last modified: 2015-03-05 08:18:45 UTC
https://www.wireshark.org/security/wnpa-sec-2015-01.html Name: WCCP dissector crash Docid: wnpa-sec-2015-01 Date: January 7, 2015 Affected versions: 1.12.0 to 1.12.2, 1.10.0 to 1.10.11 Fixed versions: 1.12.3, 1.10.12 (this includes all previous versions) References: Wireshark bug 10720 Wireshark bug 10806 CVE-2015-0559 CVE-2015-0560 Description: The WCCP dissector could crash. Impact: It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (912365) was mentioned in https://build.opensuse.org/request/show/280659 13.2+13.1 / wireshark
openSUSE-SU-2015:0113-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: openSUSE 13.2 (src): wireshark-1.12.3-8.1 openSUSE 13.1 (src): wireshark-1.10.12-32.1
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-02-19. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60550
SUSE-SU-2015:0307-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): wireshark-1.10.12-4.1 SUSE Linux Enterprise Server 12 (src): wireshark-1.10.12-4.1 SUSE Linux Enterprise Desktop 12 (src): wireshark-1.10.12-4.1
released
SUSE-SU-2015:0426-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 912365,912368,912369,912370,912372 CVE References: CVE-2015-0559,CVE-2015-0560,CVE-2015-0561,CVE-2015-0562,CVE-2015-0563,CVE-2015-0564 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Server 11 SP3 for VMware (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Server 11 SP3 (src): wireshark-1.10.12-0.2.1 SUSE Linux Enterprise Desktop 11 SP3 (src): wireshark-1.10.12-0.2.1