Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202210-04 ] Wireshark: Multiple Vulnerabilities
Date: Sun, 16 Oct 2022 14:52:50
Message-Id: 166593123064.9.1172221563923154759@90bb6a0775af
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202210-04
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Wireshark: Multiple Vulnerabilities
9 Date: October 16, 2022
10 Bugs: #802216, #824474, #830343, #833294, #869140
11 ID: 202210-04
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in Wireshark, the worst of
19 which could result in denial of service.
20
21 Background
22 ==========
23
24 Wireshark is a versatile network protocol analyzer.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-analyzer/wireshark < 3.6.8 >= 3.6.8
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in Wireshark. Please
38 review the CVE identifiers referenced below for details.
39
40 Impact
41 ======
42
43 Please review the referenced CVE identifiers for details.
44
45 Workaround
46 ==========
47
48 There is no known workaround at this time.
49
50 Resolution
51 ==========
52
53 All Wireshark users should upgrade to the latest version:
54
55 # emerge --sync
56 # emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-3.6.8"
57
58 References
59 ==========
60
61 [ 1 ] CVE-2021-4181
62 https://nvd.nist.gov/vuln/detail/CVE-2021-4181
63 [ 2 ] CVE-2021-4182
64 https://nvd.nist.gov/vuln/detail/CVE-2021-4182
65 [ 3 ] CVE-2021-4183
66 https://nvd.nist.gov/vuln/detail/CVE-2021-4183
67 [ 4 ] CVE-2021-4184
68 https://nvd.nist.gov/vuln/detail/CVE-2021-4184
69 [ 5 ] CVE-2021-4185
70 https://nvd.nist.gov/vuln/detail/CVE-2021-4185
71 [ 6 ] CVE-2021-4186
72 https://nvd.nist.gov/vuln/detail/CVE-2021-4186
73 [ 7 ] CVE-2021-4190
74 https://nvd.nist.gov/vuln/detail/CVE-2021-4190
75 [ 8 ] CVE-2021-22235
76 https://nvd.nist.gov/vuln/detail/CVE-2021-22235
77 [ 9 ] CVE-2021-39920
78 https://nvd.nist.gov/vuln/detail/CVE-2021-39920
79 [ 10 ] CVE-2021-39921
80 https://nvd.nist.gov/vuln/detail/CVE-2021-39921
81 [ 11 ] CVE-2021-39922
82 https://nvd.nist.gov/vuln/detail/CVE-2021-39922
83 [ 12 ] CVE-2021-39924
84 https://nvd.nist.gov/vuln/detail/CVE-2021-39924
85 [ 13 ] CVE-2021-39925
86 https://nvd.nist.gov/vuln/detail/CVE-2021-39925
87 [ 14 ] CVE-2021-39926
88 https://nvd.nist.gov/vuln/detail/CVE-2021-39926
89 [ 15 ] CVE-2021-39928
90 https://nvd.nist.gov/vuln/detail/CVE-2021-39928
91 [ 16 ] CVE-2021-39929
92 https://nvd.nist.gov/vuln/detail/CVE-2021-39929
93 [ 17 ] CVE-2022-0581
94 https://nvd.nist.gov/vuln/detail/CVE-2022-0581
95 [ 18 ] CVE-2022-0582
96 https://nvd.nist.gov/vuln/detail/CVE-2022-0582
97 [ 19 ] CVE-2022-0583
98 https://nvd.nist.gov/vuln/detail/CVE-2022-0583
99 [ 20 ] CVE-2022-0585
100 https://nvd.nist.gov/vuln/detail/CVE-2022-0585
101 [ 21 ] CVE-2022-0586
102 https://nvd.nist.gov/vuln/detail/CVE-2022-0586
103 [ 22 ] WNPA-SEC-2021-06
104 [ 23 ] WNPA-SEC-2022-06
105
106 Availability
107 ============
108
109 This GLSA and any updates to it are available for viewing at
110 the Gentoo Security Website:
111
112 https://security.gentoo.org/glsa/202210-04
113
114 Concerns?
115 =========
116
117 Security is a primary focus of Gentoo Linux and ensuring the
118 confidentiality and security of our users' machines is of utmost
119 importance to us. Any security concerns should be addressed to
120 security@g.o or alternatively, you may file a bug at
121 https://bugs.gentoo.org.
122
123 License
124 =======
125
126 Copyright 2022 Gentoo Foundation, Inc; referenced text
127 belongs to its owner(s).
128
129 The contents of this document are licensed under the
130 Creative Commons - Attribution / Share Alike license.
131
132 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature