Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201604-05 ] Wireshark: Multiple vulnerabilities
Date: Tue, 26 Apr 2016 21:30:47
Message-Id: 9e776159-a3cf-26a4-1f12-981af9bd02cd@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201604-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Wireshark: Multiple vulnerabilities
9 Date: April 26, 2016
10 Bugs: #570564, #575780
11 ID: 201604-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Wireshark, allowing local
19 attackers to escalate privileges and remote attackers to cause Denial
20 of Service.
21
22 Background
23 ==========
24
25 Wireshark is a network protocol analyzer formerly known as ethereal.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-analyzer/wireshark < 2.0.2 >= 2.0.2
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in Wireshark. Please
39 review the CVE identifiers referenced below for details.
40
41 Impact
42 ======
43
44 Remote attackers could cause Denial of Service and local attackers
45 could escalate privileges.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All Wireshark users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-2.0.2"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2015-8711
64 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8711
65 [ 2 ] CVE-2015-8712
66 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8712
67 [ 3 ] CVE-2015-8713
68 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8713
69 [ 4 ] CVE-2015-8714
70 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8714
71 [ 5 ] CVE-2015-8715
72 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8715
73 [ 6 ] CVE-2015-8716
74 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8716
75 [ 7 ] CVE-2015-8717
76 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8717
77 [ 8 ] CVE-2015-8718
78 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8718
79 [ 9 ] CVE-2015-8719
80 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8719
81 [ 10 ] CVE-2015-8720
82 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8720
83 [ 11 ] CVE-2015-8721
84 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8721
85 [ 12 ] CVE-2015-8722
86 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8722
87 [ 13 ] CVE-2015-8723
88 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8723
89 [ 14 ] CVE-2015-8724
90 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8724
91 [ 15 ] CVE-2015-8725
92 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8725
93 [ 16 ] CVE-2015-8726
94 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8726
95 [ 17 ] CVE-2015-8727
96 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8727
97 [ 18 ] CVE-2015-8728
98 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8728
99 [ 19 ] CVE-2015-8729
100 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8729
101 [ 20 ] CVE-2015-8730
102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8730
103 [ 21 ] CVE-2015-8731
104 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8731
105 [ 22 ] CVE-2015-8732
106 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8732
107 [ 23 ] CVE-2015-8733
108 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8733
109 [ 24 ] CVE-2015-8734
110 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8734
111 [ 25 ] CVE-2015-8735
112 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8735
113 [ 26 ] CVE-2015-8736
114 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8736
115 [ 27 ] CVE-2015-8737
116 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8737
117 [ 28 ] CVE-2015-8738
118 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8738
119 [ 29 ] CVE-2015-8739
120 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8739
121 [ 30 ] CVE-2015-8740
122 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8740
123 [ 31 ] CVE-2015-8741
124 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8741
125 [ 32 ] CVE-2015-8742
126 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8742
127 [ 33 ] CVE-2016-2521
128 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2521
129 [ 34 ] CVE-2016-2522
130 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2522
131 [ 35 ] CVE-2016-2523
132 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2523
133 [ 36 ] CVE-2016-2524
134 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2524
135 [ 37 ] CVE-2016-2525
136 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2525
137 [ 38 ] CVE-2016-2526
138 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2526
139 [ 39 ] CVE-2016-2527
140 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2527
141 [ 40 ] CVE-2016-2528
142 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2528
143 [ 41 ] CVE-2016-2529
144 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2529
145 [ 42 ] CVE-2016-2530
146 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2530
147 [ 43 ] CVE-2016-2531
148 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2531
149 [ 44 ] CVE-2016-2532
150 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-2532
151
152 Availability
153 ============
154
155 This GLSA and any updates to it are available for viewing at
156 the Gentoo Security Website:
157
158 https://security.gentoo.org/glsa/201604-05
159
160 Concerns?
161 =========
162
163 Security is a primary focus of Gentoo Linux and ensuring the
164 confidentiality and security of our users' machines is of utmost
165 importance to us. Any security concerns should be addressed to
166 security@g.o or alternatively, you may file a bug at
167 https://bugs.gentoo.org.
168
169 License
170 =======
171
172 Copyright 2016 Gentoo Foundation, Inc; referenced text
173 belongs to its owner(s).
174
175 The contents of this document are licensed under the
176 Creative Commons - Attribution / Share Alike license.
177
178 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature