Security update for wireshark

SUSE Security Update: Security update for wireshark
Announcement ID: SUSE-SU-2012:0296-1
Rating: moderate
References: #741187 #741188 #741190
Affected Products:
  • SUSE Linux Enterprise Server 10 SP4
  • SUSE Linux Enterprise Desktop 10 SP4
  • SLE SDK 10 SP4

  • An update that fixes 6 vulnerabilities is now available.

    Description:


    This version upgrade of wireshark to 1.4.11 fixes the
    following security issues:

    * CVE-2012-0043: RLC dissector buffer overflow
    * CVE-2012-0041: multiple file parser vulnerabilities
    * CVE-2012-0042: NULL pointer vulnerabilities
    * CVE-2012-0066: DoS due to too large buffer alloc
    request
    * CVE-2012-0067: DoS due to integer underflow and too
    large buffer alloc. request
    * CVE-2012-0068: memory corruption due to buffer
    underflow

    Additionally, various other non-security issues were
    resolved.

    Security Issue references:

    * CVE-2012-0041
    >
    * CVE-2012-0043
    >
    * CVE-2012-0042
    >
    * CVE-2012-0066
    >
    * CVE-2012-0067
    >
    * CVE-2012-0068
    >

    Package List:

    • SUSE Linux Enterprise Server 10 SP4 (i586 ia64 ppc s390x x86_64):
    • wireshark-1.4.11-0.5.1
    • wireshark-devel-1.4.11-0.5.1
    • SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):
    • wireshark-1.4.11-0.5.1
    • SLE SDK 10 SP4 (i586 ia64 ppc s390x x86_64):
    • wireshark-devel-1.4.11-0.5.1

    References:

    • http://support.novell.com/security/cve/CVE-2012-0041.html
    • http://support.novell.com/security/cve/CVE-2012-0042.html
    • http://support.novell.com/security/cve/CVE-2012-0043.html
    • http://support.novell.com/security/cve/CVE-2012-0066.html
    • http://support.novell.com/security/cve/CVE-2012-0067.html
    • http://support.novell.com/security/cve/CVE-2012-0068.html
    • https://bugzilla.novell.com/741187
    • https://bugzilla.novell.com/741188
    • https://bugzilla.novell.com/741190
    • http://download.suse.com/patch/finder/?keywords=0f46263d00a0a835ae8b455b8d0c12d8