SUSE-SU-2015:0307-1
Dashboard / Vulnerabilities / SUSE-SU-2015:0307-1
SUSE-SU-2015:0307-1
Summary: Security update for wireshark
Details: This update fixes the following security issues: - The following vulnerabilities allowed Wireshark to be crashed by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. + The WCCP dissector could crash wnpa-sec-2015-01 CVE-2015-0559 CVE-2015-0560 [boo#912365] + The LPP dissector could crash. wnpa-sec-2015-02 CVE-2015-0561 [boo#912368] + The DEC DNA Routing Protocol dissector could crash. wnpa-sec-2015-03 CVE-2015-0562 [boo#912369] + The SMTP dissector could crash. wnpa-sec-2015-04 CVE-2015-0563 [boo#912370] + Wireshark could crash while decypting TLS/SSL sessions. wnpa-sec-2015-05 CVE-2015-0564 [boo#912372]
References: https://www.suse.com/support/update/announcement/2015/suse-su-20150307-1/, https://bugzilla.suse.com/912365, https://bugzilla.suse.com/912368, https://bugzilla.suse.com/912369, https://bugzilla.suse.com/912370, https://bugzilla.suse.com/912372, https://www.suse.com/security/cve/CVE-2015-0559, https://www.suse.com/security/cve/CVE-2015-0560, https://www.suse.com/security/cve/CVE-2015-0561, https://www.suse.com/security/cve/CVE-2015-0562, https://www.suse.com/security/cve/CVE-2015-0563, https://www.suse.com/security/cve/CVE-2015-0564
Affected packages
Package
Name: wireshark
Purl: pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
