Alpine: tshark, multiple wireshark packages: security update to 2.0.3-r0 (deprecated)

high Tenable Cloud Security Plugin ID 400971

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the
packet-header data type, which allows remote attackers to cause a denial of service (application crash)
via a crafted packet. (CVE-2016-5358)

- epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x
before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service
(infinite loop) via a crafted packet. (CVE-2016-5350)

- epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4
mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service
(application crash) via a crafted packet. (CVE-2016-5351)

- epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length
values, which allows remote attackers to cause a denial of service (application crash) via a crafted
packet. (CVE-2016-5352)

- epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x
before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service
(application crash) via a crafted packet. (CVE-2016-5353)

See Also

https://git.alpinelinux.org/aports/commit/?id=93fab6eb95e50c1ebb9d4e7359e382149d9f5a71

https://git.alpinelinux.org/aports/commit/?id=f4e3f52ff8119918eb8b28f70da9d5b74f20af09

Plugin Details

Severity: High

ID: 400971

Version: Revision 1.22

Type: Local

Published: 8/16/2023

Updated: 1/17/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2016-5358

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2016-5350

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/5/2016

Vulnerability Publication Date: 6/7/2016

Reference Information

CVE: CVE-2016-5350, CVE-2016-5351, CVE-2016-5352, CVE-2016-5353, CVE-2016-5354, CVE-2016-5355, CVE-2016-5356, CVE-2016-5357, CVE-2016-5358

BID: 91140

IAVB: 2016-B-0105-S