Bug 935158 (CVE-2015-4652) - VUL-1: CVE-2015-4652: wireshark: GSM DTAP dissector crash (wnpa-sec-2015-20)
Summary: VUL-1: CVE-2015-4652: wireshark: GSM DTAP dissector crash (wnpa-sec-2015-20)
Status: RESOLVED FIXED
Alias: CVE-2015-4652
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.2
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-17 19:01 UTC by Andreas Stieger
Modified: 2016-04-27 20:21 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2015-06-17 19:01:56 UTC
Name: GSM DTAP dissector crash
Docid: wnpa-sec-2015-20
Date: June 17, 2015
Description: The GSM DTAP dissector could crash.
Affected versions: 1.12.0 to 1.12.x
Fixed versions: 1.12.x

(Note: wireshark does not make statements about affectedness of discontinued releases, meaning 1.10.x might be affected)

Impact: It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Reproducer (attached):
https://www.wireshark.org/download/automated/captures/fuzz-2015-05-14-29685.pcap

Fix (master):
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=d93be95fc0e7011e8b4ade9171e7e66146063296

Fix (master-1.12):
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=9fa6881060b46b6ea1a3c89529f6ebebc1caf77f

References:
https://www.wireshark.org/security/wnpa-sec-2015-20.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11201
Comment 1 Swamp Workflow Management 2015-06-17 22:00:57 UTC
bugbot adjusting priority
Comment 2 Chunyan Liu 2015-07-01 09:22:02 UTC
Tested with given pcap file on 1.10.14 (SLE-11-SP3 and SLE-12), didn't show problem. So close it.
Comment 3 Andreas Stieger 2015-07-01 09:40:25 UTC
Verified crash segmentation fault) on openSUSE 13.2 with Wireshark 1.12.5, reopening
Comment 4 Andreas Stieger 2015-07-01 09:41:40 UTC
I'll do an update for at last openSUSE 13.2 unless someone beats me to it. Wanted to fix the Factory qt5 failure first.
Comment 5 Andreas Stieger 2015-07-01 18:08:19 UTC
From openSUSE 13.2 only.
Comment 6 Andreas Stieger 2015-07-01 18:17:34 UTC
https://build.opensuse.org/request/show/314772
Comment 7 Andreas Stieger 2015-07-09 11:23:17 UTC
Fixes released for all affected versions.
Comment 8 Swamp Workflow Management 2015-07-09 12:08:56 UTC
openSUSE-SU-2015:1215-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 935157,935158
CVE References: CVE-2015-4651,CVE-2015-4652
Sources used:
openSUSE 13.2 (src):    wireshark-1.12.6-18.1
Comment 12 Swamp Workflow Management 2015-10-05 13:09:51 UTC
SUSE-SU-2015:1676-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 935158,941500
CVE References: CVE-2015-3813,CVE-2015-4652,CVE-2015-6241,CVE-2015-6242,CVE-2015-6243,CVE-2015-6244,CVE-2015-6245,CVE-2015-6246,CVE-2015-6247,CVE-2015-6248,CVE-2015-6249
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Software Development Kit 11-SP3 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Server for VMWare 11-SP3 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Server 11-SP4 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Server 11-SP3 (src):    wireshark-1.12.7-0.5.3
Comment 13 Swamp Workflow Management 2015-10-05 15:10:02 UTC
SUSE-SU-2015:1676-2: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 935158,941500
CVE References: CVE-2015-3813,CVE-2015-4652,CVE-2015-6241,CVE-2015-6242,CVE-2015-6243,CVE-2015-6244,CVE-2015-6245,CVE-2015-6246,CVE-2015-6247,CVE-2015-6248,CVE-2015-6249
Sources used:
SUSE Linux Enterprise Desktop 11-SP4 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Desktop 11-SP3 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    wireshark-1.12.7-0.5.3
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    wireshark-1.12.7-0.5.3
Comment 14 Swamp Workflow Management 2015-10-09 15:10:40 UTC
SUSE-SU-2015:1713-1: An update that fixes 10 vulnerabilities is now available.

Category: security (moderate)
Bug References: 935158,941500
CVE References: CVE-2015-3813,CVE-2015-6241,CVE-2015-6242,CVE-2015-6243,CVE-2015-6244,CVE-2015-6245,CVE-2015-6246,CVE-2015-6247,CVE-2015-6248,CVE-2015-6249
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    wireshark-1.12.7-15.1
SUSE Linux Enterprise Server 12 (src):    wireshark-1.12.7-15.1
SUSE Linux Enterprise Desktop 12 (src):    wireshark-1.12.7-15.1