Alpine: tshark, multiple wireshark packages: security update to 2.2.0-r1 (deprecated)

high Tenable Self-Hosted Container Security Plugin ID 400919

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture
file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector. (CVE-2016-7958)

- In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a
malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-
byte memcmp for potentially shorter strings. (CVE-2016-7957)

- In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network
traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input
with too many I/O objects. (CVE-2016-9372)

- In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free,
triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c
and epan/dissectors/packet-dcerpc-spoolss.c by using the wmem file scope for private strings.
(CVE-2016-9373)

See Also

https://git.alpinelinux.org/aports/commit/?id=209279633fe34947456fb0e466bfaa9efd8ae60b

https://git.alpinelinux.org/aports/commit/?id=a3c70e4154e1e81f0bd3787ff230e9ca4c3064d0

Plugin Details

Severity: High

ID: 400919

Version: Revision 1.22

Type: Local

Published: 8/16/2023

Updated: 1/17/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2016-7958

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/1/2016

Vulnerability Publication Date: 10/4/2016

Reference Information

CVE: CVE-2016-7957, CVE-2016-7958, CVE-2016-9372, CVE-2016-9373, CVE-2016-9374, CVE-2016-9375, CVE-2016-9376

BID: 93463, 94368, 94369, 97597

IAVB: 2016-B-0176-S