openSUSE Security Update: update for wireshark ______________________________________________________________________________ Announcement ID: openSUSE-SU-2013:1671-1 Rating: moderate References: #848738 Cross-References: CVE-2013-6336 CVE-2013-6337 CVE-2013-6338 CVE-2013-6339 CVE-2013-6340 Affected Products: openSUSE 12.3 openSUSE 12.2 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: the following security issues were fixed in wireshark: * The IEEE 802.15.4 dissector could crash wnpa-sec-2013-61 CVE-2013-6336 * The NBAP dissector could crash wnpa-sec-2013-62 CVE-2013-6337 * The SIP dissector could crash wnpa-sec-2013-63 CVE-2013-6338 * The OpenWire dissector could go into a large loop wnpa-sec-2013-64 CVE-2013-6339 * The TCP dissector could crash wnpa-sec-2013-65 CVE-2013-6340 + Further bug fixes and updated protocol support as listed in: https://www.wireshark.org/docs/relnotes/wireshark-1.8.11.htm l Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.3: zypper in -t patch openSUSE-2013-848 - openSUSE 12.2: zypper in -t patch openSUSE-2013-848 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 12.3 (i586 x86_64): wireshark-1.8.11-1.24.1 wireshark-debuginfo-1.8.11-1.24.1 wireshark-debugsource-1.8.11-1.24.1 wireshark-devel-1.8.11-1.24.1 - openSUSE 12.2 (i586 x86_64): wireshark-1.8.11-1.43.1 wireshark-debuginfo-1.8.11-1.43.1 wireshark-debugsource-1.8.11-1.43.1 wireshark-devel-1.8.11-1.43.1 References: http://support.novell.com/security/cve/CVE-2013-6336.html http://support.novell.com/security/cve/CVE-2013-6337.html http://support.novell.com/security/cve/CVE-2013-6338.html http://support.novell.com/security/cve/CVE-2013-6339.html http://support.novell.com/security/cve/CVE-2013-6340.html https://bugzilla.novell.com/848738