ALT-PU-2022-1368-1
Closed vulnerabilities
BDU:2021-00874
Уязвимость анализатора протокола BLIP программного обеспечения Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-00875
Уязвимость программного обеспечения Wireshark, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать аварийное завершение работы приложения
BDU:2021-00876
Уязвимость функции в epan/dissectors/packet-fbzero.c программного обеспечения Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-00884
Уязвимость функции в epan/dissectors/packet-tcp.c программного обеспечения Wireshark, позволяющая нарушителю вызвать аварийное завершение работы приложения
BDU:2021-05776
Уязвимость компонента Modbus анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05777
Уязвимость службы Bluetooth SDP анализатора трафика компьютерных сетей Wireshark , позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05801
Уязвимость службы Bluetooth DHT анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05836
Уязвимость компонента C12.22 анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05837
Уязвимость службы Bluetooth HCI_ISO анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05936
Уязвимость набора стандартов связи для коммуникации IEEE 802.11 анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05943
Уязвимость диссектора IPPUSB анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00029
Уязвимость службы Bluetooth DHT анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00213
Уязвимость программы для анализа трафика wireshark, связанная с неправильным освобождением памяти перед удалением последний ссылки, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00214
Уязвимость программы для анализа трафика wireshark, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00251
Уязвимость программы для анализа трафика wireshark, связанная с неверными вычислениями, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01849
Уязвимость диссектора DNP анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-02437
Уязвимость диссектора RTMPT анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-02438
Уязвимость диссектора BitTorrent DHT анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-02439
Уязвимость диссектора Sysdig Event анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-25862
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1882
- openSUSE-SU-2020:1882
- https://gitlab.com/wireshark/wireshark/-/commit/7f3fe6164a68b76d9988c4253b24d43f498f1753
- https://gitlab.com/wireshark/wireshark/-/commit/7f3fe6164a68b76d9988c4253b24d43f498f1753
- https://gitlab.com/wireshark/wireshark/-/issues/16816
- https://gitlab.com/wireshark/wireshark/-/issues/16816
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1b390bec14
- FEDORA-2020-1b390bec14
- FEDORA-2020-9bda6ae1cd
- FEDORA-2020-9bda6ae1cd
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-12.html
- https://www.wireshark.org/security/wnpa-sec-2020-12.html
Modified: 2024-11-21
CVE-2020-25863
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1882
- openSUSE-SU-2020:1882
- https://gitlab.com/wireshark/wireshark/-/commit/5803c7b87b3414cdb8bf502af50bb406ca774482
- https://gitlab.com/wireshark/wireshark/-/commit/5803c7b87b3414cdb8bf502af50bb406ca774482
- https://gitlab.com/wireshark/wireshark/-/issues/16741
- https://gitlab.com/wireshark/wireshark/-/issues/16741
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1b390bec14
- FEDORA-2020-1b390bec14
- FEDORA-2020-9bda6ae1cd
- FEDORA-2020-9bda6ae1cd
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-11.html
- https://www.wireshark.org/security/wnpa-sec-2020-11.html
Modified: 2024-11-21
CVE-2020-25866
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1878
- openSUSE-SU-2020:1882
- openSUSE-SU-2020:1882
- https://gitlab.com/wireshark/wireshark/-/commit/4a948427100b6c109f4ec7b4361f0d2aec5e5c3f
- https://gitlab.com/wireshark/wireshark/-/commit/4a948427100b6c109f4ec7b4361f0d2aec5e5c3f
- https://gitlab.com/wireshark/wireshark/-/issues/16866
- https://gitlab.com/wireshark/wireshark/-/issues/16866
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1bf4b97c16
- FEDORA-2020-1b390bec14
- FEDORA-2020-1b390bec14
- FEDORA-2020-9bda6ae1cd
- FEDORA-2020-9bda6ae1cd
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-13.html
- https://www.wireshark.org/security/wnpa-sec-2020-13.html
Modified: 2024-11-21
CVE-2020-26418
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26418.json
- https://gitlab.com/wireshark/wireshark/-/issues/16739
- https://gitlab.com/wireshark/wireshark/-/issues/16739
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2021-138674557c
- FEDORA-2021-138674557c
- FEDORA-2021-f3011da665
- FEDORA-2021-f3011da665
- GLSA-202101-12
- GLSA-202101-12
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-16.html
- https://www.wireshark.org/security/wnpa-sec-2020-16.html
Modified: 2024-11-21
CVE-2020-26420
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26420.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26420.json
- https://gitlab.com/wireshark/wireshark/-/issues/16994
- https://gitlab.com/wireshark/wireshark/-/issues/16994
- FEDORA-2021-138674557c
- FEDORA-2021-138674557c
- FEDORA-2021-f3011da665
- FEDORA-2021-f3011da665
- GLSA-202101-12
- GLSA-202101-12
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-18.html
- https://www.wireshark.org/security/wnpa-sec-2020-18.html
Modified: 2024-11-21
CVE-2020-26421
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26421.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-26421.json
- https://gitlab.com/wireshark/wireshark/-/issues/16958
- https://gitlab.com/wireshark/wireshark/-/issues/16958
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2021-138674557c
- FEDORA-2021-138674557c
- FEDORA-2021-f3011da665
- FEDORA-2021-f3011da665
- GLSA-202101-12
- GLSA-202101-12
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-17.html
- https://www.wireshark.org/security/wnpa-sec-2020-17.html
Modified: 2024-11-21
CVE-2020-26575
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
- https://gitlab.com/wireshark/wireshark/-/commit/3ff940652962c099b73ae3233322b8697b0d10ab
- https://gitlab.com/wireshark/wireshark/-/commit/3ff940652962c099b73ae3233322b8697b0d10ab
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/merge_requests/467
- https://gitlab.com/wireshark/wireshark/-/merge_requests/467
- https://gitlab.com/wireshark/wireshark/-/merge_requests/471
- https://gitlab.com/wireshark/wireshark/-/merge_requests/471
- https://gitlab.com/wireshark/wireshark/-/merge_requests/472
- https://gitlab.com/wireshark/wireshark/-/merge_requests/472
- https://gitlab.com/wireshark/wireshark/-/merge_requests/473
- https://gitlab.com/wireshark/wireshark/-/merge_requests/473
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-4cff262f07
- FEDORA-2020-4cff262f07
- FEDORA-2020-d4344dd12f
- FEDORA-2020-d4344dd12f
- GLSA-202011-08
- GLSA-202011-08
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.wireshark.org/security/wnpa-sec-2020-14.html
- https://www.wireshark.org/security/wnpa-sec-2020-14.html
Modified: 2024-11-21
CVE-2020-28030
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
- https://gitlab.com/wireshark/wireshark/-/commit/b287e7165e8aa89cde6ae37e7c257c5d87d16b9b
- https://gitlab.com/wireshark/wireshark/-/commit/b287e7165e8aa89cde6ae37e7c257c5d87d16b9b
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- https://gitlab.com/wireshark/wireshark/-/issues/16887
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- [debian-lts-announce] 20210206 [SECURITY] [DLA 2547-1] wireshark security update
- FEDORA-2020-4cff262f07
- FEDORA-2020-4cff262f07
- FEDORA-2020-d4344dd12f
- FEDORA-2020-d4344dd12f
- https://www.wireshark.org/security/wnpa-sec-2020-15.html
- https://www.wireshark.org/security/wnpa-sec-2020-15.html
Modified: 2024-11-21
CVE-2021-22173
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22173.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22173.json
- https://gitlab.com/wireshark/wireshark/-/issues/17124
- https://gitlab.com/wireshark/wireshark/-/issues/17124
- FEDORA-2021-f22ce64b3b
- FEDORA-2021-f22ce64b3b
- FEDORA-2021-5522a34aa0
- FEDORA-2021-5522a34aa0
- GLSA-202107-21
- GLSA-202107-21
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-01.html
- https://www.wireshark.org/security/wnpa-sec-2021-01.html
Modified: 2024-11-21
CVE-2021-22174
Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22174.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22174.json
- https://gitlab.com/wireshark/wireshark/-/issues/17165
- https://gitlab.com/wireshark/wireshark/-/issues/17165
- FEDORA-2021-f22ce64b3b
- FEDORA-2021-f22ce64b3b
- FEDORA-2021-5522a34aa0
- FEDORA-2021-5522a34aa0
- GLSA-202107-21
- GLSA-202107-21
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-02.html
- https://www.wireshark.org/security/wnpa-sec-2021-02.html
Modified: 2024-11-21
CVE-2021-22191
Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22191.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22191.json
- https://gitlab.com/wireshark/wireshark/-/issues/17232
- https://gitlab.com/wireshark/wireshark/-/issues/17232
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- GLSA-202107-21
- GLSA-202107-21
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-03.html
- https://www.wireshark.org/security/wnpa-sec-2021-03.html
Modified: 2024-11-21
CVE-2021-22207
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22207.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22207.json
- https://gitlab.com/wireshark/wireshark/-/issues/17331
- https://gitlab.com/wireshark/wireshark/-/issues/17331
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-67691ad99d
- FEDORA-2021-67691ad99d
- FEDORA-2021-6e0508d69d
- FEDORA-2021-6e0508d69d
- GLSA-202107-21
- GLSA-202107-21
- DSA-5019
- DSA-5019
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-04.html
- https://www.wireshark.org/security/wnpa-sec-2021-04.html
Modified: 2024-11-21
CVE-2021-22222
Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22222.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22222.json
- https://gitlab.com/wireshark/wireshark/-/merge_requests/3130
- https://gitlab.com/wireshark/wireshark/-/merge_requests/3130
- GLSA-202107-21
- GLSA-202107-21
- DSA-5019
- DSA-5019
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.wireshark.org/security/wnpa-sec-2021-05.html
- https://www.wireshark.org/security/wnpa-sec-2021-05.html
Modified: 2024-11-21
CVE-2021-22235
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22235.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22235.json
- https://gitlab.com/wireshark/wireshark/-/issues/17462
- https://gitlab.com/wireshark/wireshark/-/issues/17462
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-05.html
- https://www.wireshark.org/security/wnpa-sec-2021-05.html
Modified: 2024-11-21
CVE-2021-39920
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39920.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39920.json
- https://gitlab.com/wireshark/wireshark/-/issues/17705
- https://gitlab.com/wireshark/wireshark/-/issues/17705
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-15.html
- https://www.wireshark.org/security/wnpa-sec-2021-15.html
Modified: 2024-11-21
CVE-2021-39921
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39921.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39921.json
- https://gitlab.com/wireshark/wireshark/-/issues/17703
- https://gitlab.com/wireshark/wireshark/-/issues/17703
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-14.html
- https://www.wireshark.org/security/wnpa-sec-2021-14.html
Modified: 2024-11-21
CVE-2021-39922
Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39922.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39922.json
- https://gitlab.com/wireshark/wireshark/-/issues/17636
- https://gitlab.com/wireshark/wireshark/-/issues/17636
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-12.html
- https://www.wireshark.org/security/wnpa-sec-2021-12.html
Modified: 2024-11-21
CVE-2021-39923
Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39923.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39923.json
- https://gitlab.com/wireshark/wireshark/-/issues/17684
- https://gitlab.com/wireshark/wireshark/-/issues/17684
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-11.html
- https://www.wireshark.org/security/wnpa-sec-2021-11.html
Modified: 2024-11-21
CVE-2021-39924
Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39924.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39924.json
- https://gitlab.com/wireshark/wireshark/-/issues/17677
- https://gitlab.com/wireshark/wireshark/-/issues/17677
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-10.html
- https://www.wireshark.org/security/wnpa-sec-2021-10.html
Modified: 2024-11-21
CVE-2021-39925
Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39925.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39925.json
- https://gitlab.com/wireshark/wireshark/-/issues/17635
- https://gitlab.com/wireshark/wireshark/-/issues/17635
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-09.html
- https://www.wireshark.org/security/wnpa-sec-2021-09.html
Modified: 2024-11-21
CVE-2021-39926
Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39926.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39926.json
- https://gitlab.com/wireshark/wireshark/-/issues/17649
- https://gitlab.com/wireshark/wireshark/-/issues/17649
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-08.html
- https://www.wireshark.org/security/wnpa-sec-2021-08.html
Modified: 2024-11-21
CVE-2021-39928
NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39928.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39928.json
- https://gitlab.com/wireshark/wireshark/-/issues/17704
- https://gitlab.com/wireshark/wireshark/-/issues/17704
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-13.html
- https://www.wireshark.org/security/wnpa-sec-2021-13.html
Modified: 2024-11-21
CVE-2021-39929
Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39929.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39929.json
- https://gitlab.com/wireshark/wireshark/-/issues/17651
- https://gitlab.com/wireshark/wireshark/-/issues/17651
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- [debian-lts-announce] 20211226 [SECURITY] [DLA 2849-1] wireshark security update
- FEDORA-2021-3747cf6107
- FEDORA-2021-3747cf6107
- FEDORA-2021-97bd631e0a
- FEDORA-2021-97bd631e0a
- GLSA-202210-04
- GLSA-202210-04
- DSA-5019
- DSA-5019
- https://www.wireshark.org/security/wnpa-sec-2021-07.html
- https://www.wireshark.org/security/wnpa-sec-2021-07.html
Modified: 2024-11-21
CVE-2021-4181
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4181.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4181.json
- https://gitlab.com/wireshark/wireshark/-/merge_requests/5429
- https://gitlab.com/wireshark/wireshark/-/merge_requests/5429
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-30411cb3c4
- FEDORA-2022-30411cb3c4
- FEDORA-2022-1daf93c51d
- FEDORA-2022-1daf93c51d
- GLSA-202210-04
- GLSA-202210-04
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.wireshark.org/security/wnpa-sec-2021-21.html
- https://www.wireshark.org/security/wnpa-sec-2021-21.html
Modified: 2024-11-21
CVE-2021-4182
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4182.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4182.json
- https://gitlab.com/wireshark/wireshark/-/issues/17801
- https://gitlab.com/wireshark/wireshark/-/issues/17801
- FEDORA-2022-30411cb3c4
- FEDORA-2022-30411cb3c4
- FEDORA-2022-1daf93c51d
- FEDORA-2022-1daf93c51d
- GLSA-202210-04
- GLSA-202210-04
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.wireshark.org/security/wnpa-sec-2021-20.html
- https://www.wireshark.org/security/wnpa-sec-2021-20.html
Modified: 2024-11-21
CVE-2021-4183
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4183.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4183.json
- https://gitlab.com/wireshark/wireshark/-/issues/17755
- https://gitlab.com/wireshark/wireshark/-/issues/17755
- FEDORA-2022-30411cb3c4
- FEDORA-2022-30411cb3c4
- FEDORA-2022-1daf93c51d
- FEDORA-2022-1daf93c51d
- GLSA-202210-04
- GLSA-202210-04
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.wireshark.org/security/wnpa-sec-2021-19.html
- https://www.wireshark.org/security/wnpa-sec-2021-19.html
Modified: 2024-11-21
CVE-2021-4184
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4184.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4184.json
- https://gitlab.com/wireshark/wireshark/-/issues/17754
- https://gitlab.com/wireshark/wireshark/-/issues/17754
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-30411cb3c4
- FEDORA-2022-30411cb3c4
- FEDORA-2022-1daf93c51d
- FEDORA-2022-1daf93c51d
- GLSA-202210-04
- GLSA-202210-04
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.wireshark.org/security/wnpa-sec-2021-18.html
- https://www.wireshark.org/security/wnpa-sec-2021-18.html
Modified: 2024-11-21
CVE-2021-4185
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4185.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-4185.json
- https://gitlab.com/wireshark/wireshark/-/issues/17745
- https://gitlab.com/wireshark/wireshark/-/issues/17745
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-30411cb3c4
- FEDORA-2022-30411cb3c4
- FEDORA-2022-1daf93c51d
- FEDORA-2022-1daf93c51d
- GLSA-202210-04
- GLSA-202210-04
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.wireshark.org/security/wnpa-sec-2021-17.html
- https://www.wireshark.org/security/wnpa-sec-2021-17.html
Modified: 2024-11-21
CVE-2022-0581
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0581.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0581.json
- https://gitlab.com/wireshark/wireshark/-/issues/17935
- https://gitlab.com/wireshark/wireshark/-/issues/17935
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-5a3603afe0
- FEDORA-2022-5a3603afe0
- FEDORA-2022-e29665a42b
- FEDORA-2022-e29665a42b
- GLSA-202210-04
- GLSA-202210-04
- https://www.wireshark.org/security/wnpa-sec-2022-05.html
- https://www.wireshark.org/security/wnpa-sec-2022-05.html
Modified: 2024-11-21
CVE-2022-0582
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0582.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0582.json
- https://gitlab.com/wireshark/wireshark/-/issues/17882
- https://gitlab.com/wireshark/wireshark/-/issues/17882
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-5a3603afe0
- FEDORA-2022-5a3603afe0
- FEDORA-2022-e29665a42b
- FEDORA-2022-e29665a42b
- GLSA-202210-04
- GLSA-202210-04
- https://www.wireshark.org/security/wnpa-sec-2022-04.html
- https://www.wireshark.org/security/wnpa-sec-2022-04.html
Modified: 2024-11-21
CVE-2022-0583
Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0583.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0583.json
- https://gitlab.com/wireshark/wireshark/-/issues/17840
- https://gitlab.com/wireshark/wireshark/-/issues/17840
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-5a3603afe0
- FEDORA-2022-5a3603afe0
- FEDORA-2022-e29665a42b
- FEDORA-2022-e29665a42b
- GLSA-202210-04
- GLSA-202210-04
- https://www.wireshark.org/security/wnpa-sec-2022-03.html
- https://www.wireshark.org/security/wnpa-sec-2022-03.html
Modified: 2024-11-21
CVE-2022-0585
Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0585.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0585.json
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-5a3603afe0
- FEDORA-2022-5a3603afe0
- FEDORA-2022-e29665a42b
- FEDORA-2022-e29665a42b
- GLSA-202210-04
- GLSA-202210-04
- https://www.wireshark.org/security/wnpa-sec-2022-02.html
- https://www.wireshark.org/security/wnpa-sec-2022-02.html
Modified: 2024-11-21
CVE-2022-0586
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0586.json
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-0586.json
- https://gitlab.com/wireshark/wireshark/-/issues/17813
- https://gitlab.com/wireshark/wireshark/-/issues/17813
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- [debian-lts-announce] 20220331 [SECURITY] [DLA 2967-1] wireshark security update
- FEDORA-2022-5a3603afe0
- FEDORA-2022-5a3603afe0
- FEDORA-2022-e29665a42b
- FEDORA-2022-e29665a42b
- GLSA-202210-04
- GLSA-202210-04
- https://www.wireshark.org/security/wnpa-sec-2022-01.html
- https://www.wireshark.org/security/wnpa-sec-2022-01.html