openSUSE Security Update: wireshark 1.6.2 fixing multiple issues ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:1142-1 Rating: moderate References: #697516 #706728 #718032 Cross-References: CVE-2011-1957 CVE-2011-1958 CVE-2011-1959 CVE-2011-2174 CVE-2011-2175 CVE-2011-2597 CVE-2011-2698 CVE-2011-3266 CVE-2011-3360 CVE-2011-3483 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. It includes one version update. Description: This update of wireshark fixes the following vulnerabilities: - CVE-2011-3266: Wireshark IKE dissector vulnerability - CVE-2011-3360: Wireshark Lua script execution vulnerability - CVE-2011-3483: Wireshark buffer exception handling vulnerability - CVE-2011-2597: Lucent/Ascend file parser susceptible to infinite loop - CVE-2011-2698: ANSI MAP dissector susceptible to infinite loop - CVE-2011-1957: Large/infinite loop in the DICOM dissector - CVE-2011-1959: A corrupted snoop file could crash Wireshark - CVE-2011-2174: Malformed compressed capture data could crash Wireshark - CVE-2011-2175: A corrupted Visual Networks file could crash Wireshark - CVE-2011-1958: dereferene a NULL pointer if we had a corrupted Diameter dictionary Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch wireshark-5278 - openSUSE 11.3: zypper in -t patch wireshark-5278 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586 x86_64) [New Version: 1.4.4]: wireshark-1.4.4-0.7.1 wireshark-devel-1.4.4-0.7.1 - openSUSE 11.3 (i586 x86_64) [New Version: 1.4.4]: wireshark-1.4.4-0.6.1 wireshark-devel-1.4.4-0.6.1 References: http://support.novell.com/security/cve/CVE-2011-1957.html http://support.novell.com/security/cve/CVE-2011-1958.html http://support.novell.com/security/cve/CVE-2011-1959.html http://support.novell.com/security/cve/CVE-2011-2174.html http://support.novell.com/security/cve/CVE-2011-2175.html http://support.novell.com/security/cve/CVE-2011-2597.html http://support.novell.com/security/cve/CVE-2011-2698.html http://support.novell.com/security/cve/CVE-2011-3266.html http://support.novell.com/security/cve/CVE-2011-3360.html http://support.novell.com/security/cve/CVE-2011-3483.html https://bugzilla.novell.com/697516 https://bugzilla.novell.com/706728 https://bugzilla.novell.com/718032