ALT-BU-2014-2595-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-7112
The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-sip.c?r1=51738&r2=51737&pathrev=51738
- http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-sip.c?r1=51738&r2=51737&pathrev=51738
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=51738
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=51738
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0017
- openSUSE-SU-2014:0017
- openSUSE-SU-2014:0020
- openSUSE-SU-2014:0020
- RHSA-2014:0341
- RHSA-2014:0341
- RHSA-2014:0342
- RHSA-2014:0342
- 56285
- 56285
- 56313
- 56313
- MDVSA-2013:296
- MDVSA-2013:296
- http://www.wireshark.org/security/wnpa-sec-2013-66.html
- http://www.wireshark.org/security/wnpa-sec-2013-66.html
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9388
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9388
Modified: 2024-11-21
CVE-2013-7113
epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- http://anonsvn.wireshark.org/viewvc/trunk-1.10/epan/dissectors/packet-bssgp.c?r1=53803&r2=53802&pathrev=53803
- http://anonsvn.wireshark.org/viewvc/trunk-1.10/epan/dissectors/packet-bssgp.c?r1=53803&r2=53802&pathrev=53803
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53803
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53803
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0017
- openSUSE-SU-2014:0017
- 56052
- 56052
- 56313
- 56313
- DSA-2825
- DSA-2825
- http://www.wireshark.org/security/wnpa-sec-2013-67.html
- http://www.wireshark.org/security/wnpa-sec-2013-67.html
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9488
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9488
Modified: 2024-11-21
CVE-2013-7114
Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name in a packet.
- http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ntlmssp.c?r1=53626&r2=53625&pathrev=53626
- http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-ntlmssp.c?r1=53626&r2=53625&pathrev=53626
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53626
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53626
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0013
- openSUSE-SU-2014:0017
- openSUSE-SU-2014:0017
- openSUSE-SU-2014:0020
- openSUSE-SU-2014:0020
- RHSA-2014:0342
- RHSA-2014:0342
- 56052
- 56052
- 56285
- 56285
- 56313
- 56313
- DSA-2825
- DSA-2825
- MDVSA-2013:296
- MDVSA-2013:296
- http://www.wireshark.org/security/wnpa-sec-2013-68.html
- http://www.wireshark.org/security/wnpa-sec-2013-68.html
Modified: 2024-11-21
CVE-2014-4174
wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.
- http://anonsvn.wireshark.org/viewvc/trunk-1.10/wiretap/libpcap.c?r1=53123&r2=53122&pathrev=53123
- http://anonsvn.wireshark.org/viewvc/trunk-1.10/wiretap/libpcap.c?r1=53123&r2=53122&pathrev=53123
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53123
- http://anonsvn.wireshark.org/viewvc?view=revision&revision=53123
- http://www.wireshark.org/security/wnpa-sec-2014-05.html
- http://www.wireshark.org/security/wnpa-sec-2014-05.html
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8808
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=8808
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9390
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9390
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9753
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=9753