MGASA-2014-0326

Source
https://advisories.mageia.org/MGASA-2014-0326.html
Import Source
https://advisories.mageia.org/MGASA-2014-0326.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0326
Related
Published
2014-08-12T09:16:46Z
Modified
2014-08-12T09:00:23Z
Summary
Updated wireshark package fix security vulnerabilities
Details

The Catapult DCT2000 and IrDA dissectors could underrun a buffer (CVE-2014-5161, CVE-2014-5162).

The GSM Management dissector could crash (CVE-2014-5163).

The RLC dissector could crash (CVE-2014-5164).

The ASN.1 BER dissector could crash (CVE-2014-5165).

The wireshark package has been updated to version 1.10.9 to fix these issues and other bugs.

References
Credits

Affected packages

Mageia:4 / wireshark

Package

Name
wireshark
Purl
pkg:rpm/mageia/wireshark?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.9-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:3 / wireshark

Package

Name
wireshark
Purl
pkg:rpm/mageia/wireshark?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.10.9-1.mga3

Ecosystem specific

{
    "section": "core"
}