Upstream information

CVE-2013-1576 at MITRE

Description

The dissect_sdp_media_attribute function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly process crypto-suite parameters, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 2.9
Vector AV:A/AC:M/Au:N/C:N/I:N/A:P
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 801131 [RESOLVED / FIXED]

SUSE Security Advisories:

    openSUSE-SU-2013:0276-1 openSUSE-SU-2013:0285-1

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP2
  • wireshark >= 1.8.12-0.2.1
  • wireshark >= 1.8.5-0.2.1
  • wireshark-devel >= 1.8.5-0.2.1
Patchnames:
sdksp2-wireshark
sledsp2-wireshark
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Server for SAP Applications 11 SP4
SUSE Linux Enterprise Software Development Kit 11 SP4
  • wireshark >= 1.10.13-0.2.1
  • wireshark-devel >= 1.10.13-0.2.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA wireshark-1.10.13-0.2.1
SUSE Linux Enterprise Desktop 12 SP1
  • wireshark >= 1.12.7-15.1
  • wireshark-devel >= 1.12.7-15.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA wireshark-1.12.7-15.1
SUSE Linux Enterprise Software Development Kit 12 SP1 GA wireshark-devel-1.12.7-15.1
SUSE Linux Enterprise Desktop 12 SP2
  • wireshark >= 1.12.13-31.1
  • wireshark-devel >= 1.12.13-31.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA wireshark-1.12.13-31.1
SUSE Linux Enterprise Software Development Kit 12 SP2 GA wireshark-devel-1.12.13-31.1
SUSE Linux Enterprise Desktop 12 SP3
  • libwireshark8 >= 2.2.7-47.1
  • libwiretap6 >= 2.2.7-47.1
  • libwscodecs1 >= 2.2.7-47.1
  • libwsutil7 >= 2.2.7-47.1
  • wireshark >= 2.2.7-47.1
  • wireshark-devel >= 2.2.7-47.1
  • wireshark-gtk >= 2.2.7-47.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA libwireshark8-2.2.7-47.1
SUSE Linux Enterprise Software Development Kit 12 SP3 GA wireshark-devel-2.2.7-47.1
SUSE Linux Enterprise Desktop 12 SP4
  • libwireshark9 >= 2.4.9-48.29.1
  • libwiretap7 >= 2.4.9-48.29.1
  • libwscodecs1 >= 2.4.9-48.29.1
  • libwsutil8 >= 2.4.9-48.29.1
  • wireshark >= 2.4.9-48.29.1
  • wireshark-devel >= 2.4.9-48.29.1
  • wireshark-gtk >= 2.4.9-48.29.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP4 GA libwireshark9-2.4.9-48.29.1
SUSE Linux Enterprise Software Development Kit 12 SP4 GA wireshark-devel-2.4.9-48.29.1
SUSE Linux Enterprise Desktop 12
  • wireshark >= 1.10.9-1.11
  • wireshark-devel >= 1.10.9-1.11
Patchnames:
SUSE Linux Enterprise Desktop 12 GA wireshark-1.10.9-1.11
SUSE Linux Enterprise Software Development Kit 12 GA wireshark-devel-1.10.9-1.11
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
  • libwireshark9 >= 2.4.6-1.31
  • libwiretap7 >= 2.4.6-1.31
  • libwscodecs1 >= 2.4.6-1.31
  • libwsutil8 >= 2.4.6-1.31
  • wireshark >= 2.4.6-1.31
  • wireshark-devel >= 2.4.6-1.31
  • wireshark-ui-qt >= 2.4.6-1.31
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 GA libwireshark9-2.4.6-1.31
SUSE Linux Enterprise Module for Desktop Applications 15 GA wireshark-devel-2.4.6-1.31
SUSE Linux Enterprise High Performance Computing 12 SP5
  • libwireshark9 >= 2.4.16-48.51.1
  • libwiretap7 >= 2.4.16-48.51.1
  • libwscodecs1 >= 2.4.16-48.51.1
  • libwsutil8 >= 2.4.16-48.51.1
  • wireshark >= 2.4.16-48.51.1
  • wireshark-gtk >= 2.4.16-48.51.1
Patchnames:
SUSE Linux Enterprise High Performance Computing 12 SP5 GA libwireshark9-2.4.16-48.51.1
SUSE Linux Enterprise Module for Basesystem 15
  • libwireshark9 >= 2.4.6-1.31
  • libwiretap7 >= 2.4.6-1.31
  • libwscodecs1 >= 2.4.6-1.31
  • libwsutil8 >= 2.4.6-1.31
  • wireshark >= 2.4.6-1.31
Patchnames:
SUSE Linux Enterprise Module for Basesystem 15 GA libwireshark9-2.4.6-1.31
SUSE Linux Enterprise Module for Desktop Applications 15
  • wireshark-devel >= 2.4.6-1.31
  • wireshark-ui-qt >= 2.4.6-1.31
Patchnames:
SUSE Linux Enterprise Module for Desktop Applications 15 GA wireshark-devel-2.4.6-1.31
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server for SAP Applications 11 SP2
  • wireshark >= 1.8.12-0.2.1
  • wireshark >= 1.8.5-0.2.1
  • wireshark-devel >= 1.8.5-0.2.1
Patchnames:
sdksp2-wireshark
slessp2-wireshark
SUSE Linux Enterprise Server 11 SP3
  • wireshark >= 1.8.6-0.2.1
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA wireshark-1.8.6-0.2.1
SUSE Linux Enterprise Server 11 SP4
  • wireshark >= 1.10.13-0.2.1
  • wireshark-devel >= 1.10.13-0.2.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA wireshark-1.10.13-0.2.1
SUSE Linux Enterprise Software Development Kit 11 SP4 GA wireshark-1.10.13-0.2.1
SUSE Linux Enterprise Server 12 SP1
  • wireshark >= 1.12.7-15.1
  • wireshark-devel >= 1.12.7-15.1
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA wireshark-1.12.7-15.1
SUSE Linux Enterprise Software Development Kit 12 SP1 GA wireshark-devel-1.12.7-15.1
SUSE Linux Enterprise Server 12 SP2
  • wireshark >= 1.12.13-31.1
  • wireshark-devel >= 1.12.13-31.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA wireshark-1.12.13-31.1
SUSE Linux Enterprise Software Development Kit 12 SP2 GA wireshark-devel-1.12.13-31.1
SUSE Linux Enterprise Server 12 SP3
  • libwireshark8 >= 2.2.7-47.1
  • libwiretap6 >= 2.2.7-47.1
  • libwscodecs1 >= 2.2.7-47.1
  • libwsutil7 >= 2.2.7-47.1
  • wireshark >= 2.2.7-47.1
  • wireshark-devel >= 2.2.7-47.1
  • wireshark-gtk >= 2.2.7-47.1
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA libwireshark8-2.2.7-47.1
SUSE Linux Enterprise Software Development Kit 12 SP3 GA wireshark-devel-2.2.7-47.1
SUSE Linux Enterprise Server 12 SP4
  • libwireshark9 >= 2.4.9-48.29.1
  • libwiretap7 >= 2.4.9-48.29.1
  • libwscodecs1 >= 2.4.9-48.29.1
  • libwsutil8 >= 2.4.9-48.29.1
  • wireshark >= 2.4.9-48.29.1
  • wireshark-devel >= 2.4.9-48.29.1
  • wireshark-gtk >= 2.4.9-48.29.1
Patchnames:
SUSE Linux Enterprise Server 12 SP4 GA libwireshark9-2.4.9-48.29.1
SUSE Linux Enterprise Software Development Kit 12 SP4 GA wireshark-devel-2.4.9-48.29.1
SUSE Linux Enterprise Server 12 SP5
  • libwireshark9 >= 2.4.16-48.51.1
  • libwiretap7 >= 2.4.16-48.51.1
  • libwscodecs1 >= 2.4.16-48.51.1
  • libwsutil8 >= 2.4.16-48.51.1
  • wireshark >= 2.4.16-48.51.1
  • wireshark-devel >= 2.4.16-48.51.1
  • wireshark-gtk >= 2.4.16-48.51.1
Patchnames:
SUSE Linux Enterprise Server 12 SP5 GA libwireshark9-2.4.16-48.51.1
SUSE Linux Enterprise Software Development Kit 12 SP5 GA wireshark-devel-2.4.16-48.51.1
SUSE Linux Enterprise Server 12
  • wireshark >= 1.10.9-1.5
  • wireshark-devel >= 1.10.9-1.11
Patchnames:
SUSE Linux Enterprise Server 12 GA wireshark-1.10.9-1.11
SUSE Linux Enterprise Software Development Kit 12 GA wireshark-devel-1.10.9-1.11
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • wireshark >= 1.12.13-31.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA wireshark-1.12.13-31.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP1
  • wireshark-devel >= 1.12.7-15.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA wireshark-devel-1.12.7-15.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP2
  • wireshark-devel >= 1.12.13-31.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA wireshark-devel-1.12.13-31.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP3
  • wireshark-devel >= 2.2.7-47.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA wireshark-devel-2.2.7-47.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP4
  • wireshark-devel >= 2.4.9-48.29.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP4 GA wireshark-devel-2.4.9-48.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
  • wireshark-devel >= 2.4.16-48.51.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP5 GA wireshark-devel-2.4.16-48.51.1
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
  • wireshark-devel >= 1.10.9-1.11
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA wireshark-devel-1.10.9-1.11
SUSE Linux Enterprise Software Development Kit 11 SP2
  • wireshark >= 1.8.12-0.2.1
  • wireshark-devel >= 1.8.5-0.2.1
Patchnames:
sdksp2-wireshark
openSUSE Tumbleweed
  • wireshark >= 2.2.2-1.1
  • wireshark-devel >= 2.2.2-1.1
  • wireshark-ui-gtk >= 2.2.2-1.1
  • wireshark-ui-qt >= 2.2.2-1.1
Patchnames:
openSUSE-Tumbleweed-2024-10199


SUSE Timeline for this CVE

CVE page created: Fri Jun 28 13:28:34 2013
CVE page last modified: Thu Jul 25 12:21:29 2024