SUSE-SU-2024:3165-1
Dashboard / Vulnerabilities / SUSE-SU-2024:3165-1
SUSE-SU-2024:3165-1
Summary: Security update for wireshark
Details: This update for wireshark fixes the following issues: wireshark was updated from version 3.6.23 to version 4.2.6 (jsc#PED-8517): - Security issues fixed with this update: * CVE-2024-0207: HTTP3 dissector crash (bsc#1218503) * CVE-2024-0210: Zigbee TLV dissector crash (bsc#1218506) * CVE-2024-0211: DOCSIS dissector crash (bsc#1218507) * CVE-2023-6174: Fixed SSH dissector crash (bsc#1217247) * CVE-2023-6175: NetScreen file parser crash (bsc#1217272) * CVE-2023-5371: RTPS dissector memory leak (bsc#1215959) * CVE-2023-3649: iSCSI dissector crash (bsc#1213318) * CVE-2023-2854: BLF file parser crash (bsc#1211708) * CVE-2023-0666: RTPS dissector crash (bsc#1211709) * CVE-2023-0414: EAP dissector crash (bsc#1207666) - Major changes introduced with versions 4.2.0 and 4.0.0: * Version 4.2.0 https://www.wireshark.org/docs/relnotes/wireshark-4.2.0.html * Version 4.0.0 https://www.wireshark.org/docs/relnotes/wireshark-4.0.0.html - Added an aditional desktopfile to start wireshark which asks for the super user password.
References: https://www.suse.com/support/update/announcement/2024/suse-su-20243165-1/, https://bugzilla.suse.com/1207666, https://bugzilla.suse.com/1211708, https://bugzilla.suse.com/1211709, https://bugzilla.suse.com/1213318, https://bugzilla.suse.com/1215959, https://bugzilla.suse.com/1217247, https://bugzilla.suse.com/1217272, https://bugzilla.suse.com/1218503, https://bugzilla.suse.com/1218506, https://bugzilla.suse.com/1218507, https://bugzilla.suse.com/1222030, https://www.suse.com/security/cve/CVE-2023-0414, https://www.suse.com/security/cve/CVE-2023-0666, https://www.suse.com/security/cve/CVE-2023-2854, https://www.suse.com/security/cve/CVE-2023-3649, https://www.suse.com/security/cve/CVE-2023-5371, https://www.suse.com/security/cve/CVE-2023-6174, https://www.suse.com/security/cve/CVE-2023-6175, https://www.suse.com/security/cve/CVE-2024-0207, https://www.suse.com/security/cve/CVE-2024-0210, https://www.suse.com/security/cve/CVE-2024-0211, https://www.suse.com/security/cve/CVE-2024-2955
Affected packages
Package
Name: wireshark
Purl: pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6
Affected ranges
Type: ECOSYSTEM
Events:
