openSUSE Security Update : wireshark (openSUSE-SU-2014:1503-1)

Medium Nessus Plugin ID 79592

Synopsis

The remote openSUSE host is missing a security update.

Description

wireshark was updated to fix five security issues. 	 These security issues were fixed :

- SigComp UDVM buffer overflow (CVE-2014-8710).

- AMQP crash (CVE-2014-8711).

- NCP crashes (CVE-2014-8712, CVE-2014-8713).

- TN5250 infinite loops (CVE-2014-8714).

For openSUSE 12.3 and 13.1 further bug fixes and updated protocol support are described in:
https://www.wireshark.org/docs/relnotes/wireshark-1.10.11.html

For openSUSE 13.2 further bug fixes and updated protocol support are described in:
https://www.wireshark.org/docs/relnotes/wireshark-1.12.2.html

Solution

Update the affected wireshark packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=905245

https://bugzilla.opensuse.org/show_bug.cgi?id=905246

https://bugzilla.opensuse.org/show_bug.cgi?id=905247

https://bugzilla.opensuse.org/show_bug.cgi?id=905248

https://lists.opensuse.org/opensuse-updates/2014-11/msg00104.html

https://www.wireshark.org/docs/relnotes/wireshark-1.10.11.html

https://www.wireshark.org/docs/relnotes/wireshark-1.12.2.html

Plugin Details

Severity: Medium

ID: 79592

File Name: openSUSE-2014-717.nasl

Version: 1.6

Type: local

Agent: unix

Published: 2014/11/27

Updated: 2020/06/04

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:wireshark, p-cpe:/a:novell:opensuse:wireshark-debuginfo, p-cpe:/a:novell:opensuse:wireshark-debugsource, p-cpe:/a:novell:opensuse:wireshark-devel, p-cpe:/a:novell:opensuse:wireshark-ui-gtk, p-cpe:/a:novell:opensuse:wireshark-ui-gtk-debuginfo, p-cpe:/a:novell:opensuse:wireshark-ui-qt, p-cpe:/a:novell:opensuse:wireshark-ui-qt-debuginfo, cpe:/o:novell:opensuse:12.3, cpe:/o:novell:opensuse:13.1, cpe:/o:novell:opensuse:13.2

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 2014/11/17

Reference Information

CVE: CVE-2014-8710, CVE-2014-8711, CVE-2014-8712, CVE-2014-8713, CVE-2014-8714