Bugzilla – Bug 991012
VUL-1: CVE-2016-6504: wireshark: NDS dissector crash (wnpa-sec-2016-40)
Last modified: 2018-10-13 16:01:21 UTC
Wireshark 2.0.5 and 1.12.13 https://www.wireshark.org/lists/wireshark-announce/201607/msg00001.html https://www.wireshark.org/lists/wireshark-announce/201607/msg00002.html It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. Affects 1.12.0 to 1.12.12, fixed in 1.12.13. https://www.wireshark.org/security/wnpa-sec-2016-40.html https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12576
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (991012) was mentioned in https://build.opensuse.org/request/show/415701 13.2+42.1 / wireshark
This is an autogenerated message for OBS integration: This bug (991012) was mentioned in https://build.opensuse.org/request/show/416464 13.2+42.1 / wireshark
openSUSE-SU-2016:1974-1: An update that fixes 8 vulnerabilities is now available. Category: security (low) Bug References: 991012,991013,991015,991016,991017,991018,991019,991020 CVE References: CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511 Sources used: openSUSE Leap 42.1 (src): wireshark-1.12.13-29.1 openSUSE 13.2 (src): wireshark-1.12.13-44.1
verified, it is fixed in git tag 1.12.13, commit 9eacbb4d48df647648127b9258f9e5aeeb0c7d99, will update to version 1.12.13
MR sent to SLES11 Update and SLES12 Update: https://build.suse.de/request/show/119844 https://build.suse.de/request/show/119843 Assigned to security-team@suse.de, please re-assign this bug to me after you finished you work, for my track.Thanks
SUSE-SU-2016:2212-1: An update that fixes 18 vulnerabilities is now available. Category: security (moderate) Bug References: 983671,991012,991013,991015,991016,991017,991018,991019,991020 CVE References: CVE-2016-5350,CVE-2016-5351,CVE-2016-5352,CVE-2016-5353,CVE-2016-5354,CVE-2016-5355,CVE-2016-5356,CVE-2016-5357,CVE-2016-5358,CVE-2016-5359,CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): wireshark-1.12.13-0.23.1 SUSE Linux Enterprise Server 11-SP4 (src): wireshark-1.12.13-0.23.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): wireshark-1.12.13-0.23.1
SUSE-SU-2016:2453-1: An update that fixes 18 vulnerabilities is now available. Category: security (moderate) Bug References: 983671,991012,991013,991015,991016,991017,991018,991019,991020 CVE References: CVE-2016-5350,CVE-2016-5351,CVE-2016-5352,CVE-2016-5353,CVE-2016-5354,CVE-2016-5355,CVE-2016-5356,CVE-2016-5357,CVE-2016-5358,CVE-2016-5359,CVE-2016-6504,CVE-2016-6505,CVE-2016-6506,CVE-2016-6507,CVE-2016-6508,CVE-2016-6509,CVE-2016-6510,CVE-2016-6511 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP1 (src): wireshark-1.12.13-31.1 SUSE Linux Enterprise Server 12-SP1 (src): wireshark-1.12.13-31.1 SUSE Linux Enterprise Desktop 12-SP1 (src): wireshark-1.12.13-31.1
This is an autogenerated message for OBS integration: This bug (991012) was mentioned in https://build.opensuse.org/request/show/641836 42.3 / wireshark