New Debian wireshark 2.6.20-0+deb9u2 fixes: This update addresses the following issues: * MS-WSP dissector excessive memory consumption (CVE-2021-22207) * DNP dissector crash (CVE-2021-22235) * modbus dissector crash (CVE-2021-39921) * C12.22 dissector crash (CVE-2021-39922) * PNRP dissector large loop (CVE-2021-39923) * bluetooth DHT dissector large loop (CVE-2021-39924) * bluetooth SDP dissector crash (CVE-2021-39925) * IEEE 802.11 dissector crash (CVE-2021-39928) * bluetooth DHT dissector crash (CVE-2021-39929)
--- mirror/ftp/4.4/unmaintained/4.4-8/source/wireshark_2.6.20-0+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/wireshark_2.6.20-0+deb9u2.dsc @@ -1,3 +1,18 @@ +2.6.20-0+deb9u2 [Sun, 26 Dec 2021 15:31:06 +0200] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the LTS team. + * CVE-2021-22207: Excessive memory consumption in the MS-WSP dissector. + * CVE-2021-22235: Crash in the DNP dissector. + * CVE-2021-39921: NULL pointer exception in the Modbus dissector. + * CVE-2021-39922: Buffer overflow in the C12.22 dissector. + * CVE-2021-39923: Large loop in the PNRP dissector. + * CVE-2021-39924: Large loop in the Bluetooth DHT dissector. + * CVE-2021-39928: NULL pointer exception in the IEEE 802.11 dissector. + * CVE-2021-39929: Uncontrolled Recursion in the Bluetooth DHT dissector. + + [ Balint Reczey ] + * Fix buffer overflow in the Bluetooth SDP dissector (CVE-2021-39925) + 2.6.20-0+deb9u1 [Sun, 31 Jan 2021 19:44:22 +0200] Adrian Bunk <bunk@debian.org>: * Non-maintainer upload. <http://piuparts.knut.univention.de/4.4-8/#1830791323757292536>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] e68952bd55 Bug #54284: wireshark 2.6.20-0+deb9u2 doc/errata/staging/wireshark.yaml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1144>