ALT-PU-2016-1621-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-5350
epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://github.com/wireshark/wireshark/commit/b4d16b4495b732888e12baf5b8a7e9bf2665e22b
- https://github.com/wireshark/wireshark/commit/b4d16b4495b732888e12baf5b8a7e9bf2665e22b
- https://www.wireshark.org/security/wnpa-sec-2016-29.html
- https://www.wireshark.org/security/wnpa-sec-2016-29.html
Modified: 2024-11-21
CVE-2016-5351
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11585
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=11585
- https://github.com/wireshark/wireshark/commit/9b0b20b8d5f8c9f7839d58ff6c5900f7e19283b4
- https://github.com/wireshark/wireshark/commit/9b0b20b8d5f8c9f7839d58ff6c5900f7e19283b4
- https://www.wireshark.org/security/wnpa-sec-2016-30.html
- https://www.wireshark.org/security/wnpa-sec-2016-30.html
Modified: 2024-11-21
CVE-2016-5352
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12175
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12175
- https://github.com/wireshark/wireshark/commit/b6d838eebf4456192360654092e5587c5207f185
- https://github.com/wireshark/wireshark/commit/b6d838eebf4456192360654092e5587c5207f185
- https://www.wireshark.org/security/wnpa-sec-2016-31.html
- https://www.wireshark.org/security/wnpa-sec-2016-31.html
Modified: 2024-11-21
CVE-2016-5353
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12191
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12191
- https://github.com/wireshark/wireshark/commit/7d7190695ce2ff269fdffb04e87139995cde21f4
- https://github.com/wireshark/wireshark/commit/7d7190695ce2ff269fdffb04e87139995cde21f4
- https://www.wireshark.org/security/wnpa-sec-2016-32.html
- https://www.wireshark.org/security/wnpa-sec-2016-32.html
Modified: 2024-11-21
CVE-2016-5354
The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12356
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12356
- https://github.com/wireshark/wireshark/commit/2cb5985bf47bdc8bea78d28483ed224abdd33dc6
- https://github.com/wireshark/wireshark/commit/2cb5985bf47bdc8bea78d28483ed224abdd33dc6
- https://www.wireshark.org/security/wnpa-sec-2016-33.html
- https://www.wireshark.org/security/wnpa-sec-2016-33.html
Modified: 2024-11-21
CVE-2016-5355
wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12394
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12394
- https://github.com/wireshark/wireshark/commit/3270dfac43da861c714df76513456b46765ff47f
- https://github.com/wireshark/wireshark/commit/3270dfac43da861c714df76513456b46765ff47f
- https://github.com/wireshark/wireshark/commit/5efb45231671baa2db2011d8f67f9d6e72bc455b
- https://github.com/wireshark/wireshark/commit/5efb45231671baa2db2011d8f67f9d6e72bc455b
- https://www.wireshark.org/security/wnpa-sec-2016-34.html
- https://www.wireshark.org/security/wnpa-sec-2016-34.html
Modified: 2024-11-21
CVE-2016-5356
wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12395
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12395
- https://github.com/wireshark/wireshark/commit/a66628e425db725df1ac52a3c573a03357060ddd
- https://github.com/wireshark/wireshark/commit/a66628e425db725df1ac52a3c573a03357060ddd
- https://github.com/wireshark/wireshark/commit/f5ec0afb766f19519ea9623152cca3bbe2229500
- https://github.com/wireshark/wireshark/commit/f5ec0afb766f19519ea9623152cca3bbe2229500
- https://www.wireshark.org/security/wnpa-sec-2016-35.html
- https://www.wireshark.org/security/wnpa-sec-2016-35.html
Modified: 2024-11-21
CVE-2016-5357
wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
- DSA-3615
- DSA-3615
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12396
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12396
- https://github.com/wireshark/wireshark/commit/11edc83b98a61e890d7bb01855389d40e984ea82
- https://github.com/wireshark/wireshark/commit/11edc83b98a61e890d7bb01855389d40e984ea82
- https://github.com/wireshark/wireshark/commit/6a140eca7b78b230f1f90a739a32257476513c78
- https://github.com/wireshark/wireshark/commit/6a140eca7b78b230f1f90a739a32257476513c78
- https://www.wireshark.org/security/wnpa-sec-2016-36.html
- https://www.wireshark.org/security/wnpa-sec-2016-36.html
Modified: 2024-11-21
CVE-2016-5358
epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- [oss-security] 20160609 Re: CVE Request: wireshark releases
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- 91140
- 91140
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12440
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12440
- https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7
- https://github.com/wireshark/wireshark/commit/2c13e97d656c1c0ac4d76eb9d307664aae0e0cf7
- https://www.wireshark.org/security/wnpa-sec-2016-37.html
- https://www.wireshark.org/security/wnpa-sec-2016-37.html