Univention Bugzilla – Bug 54652
wireshark: Multiple issues (4.4)
Last modified: 2022-04-13 15:13:07 CEST
New Debian wireshark 2.6.20-0+deb9u3 fixes: This update addresses the following issues: * Sysdig Event dissector crash (CVE-2021-4181) * BitTorrent DHT dissector infinite loop (CVE-2021-4184) * RTMPT dissector infinite loop (CVE-2021-4185) * improper URL handling may lead to remote code execution (CVE-2021-22191) * CMS dissector crash (CVE-2022-0581) * CSN.1 dissector crash (CVE-2022-0582) * PVFS dissector crash (CVE-2022-0583) * Large loops in multiple dissectors (CVE-2022-0585) * RTMPT dissector infinite loop (CVE-2022-0586)
--- mirror/ftp/4.4/unmaintained/component/4.4-8-errata/source/wireshark_2.6.20-0+deb9u2.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/wireshark_2.6.20-0+deb9u3.dsc @@ -1,3 +1,17 @@ +2.6.20-0+deb9u3 [Thu, 31 Mar 2022 22:01:38 +0200] Markus Koschany <apo@debian.org>: + + * Non-maintainer upload by the LTS team. + * Fix the following CVE: + * CVE-2021-4181: Crash in the Sysdig Event dissector. + * CVE-2021-4184: Infinite loop in the BitTorrent DHT dissector. + * CVE-2021-4185: Infinite loop in the RTMPT dissector. + * CVE-2021-22191: Improper URL handling in Wireshark. + * CVE-2022-0581: Crash in the CMS protocol dissector. + * CVE-2022-0582: Unaligned access in the CSN.1 protocol dissector. + * CVE-2022-0583: Crash in the PVFS protocol dissector. + * CVE-2022-0585: Large loops in multiple protocol dissectors. + * CVE-2022-0586: Infinite loop in RTMPT protocol dissector. + 2.6.20-0+deb9u2 [Sun, 26 Dec 2021 15:31:06 +0200] Adrian Bunk <bunk@debian.org>: * Non-maintainer upload by the LTS team. <http://piuparts.knut.univention.de/4.4-8/#1830791323756210011>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 410c6715cb Bug #54652: wireshark 2.6.20-0+deb9u3 doc/errata/staging/wireshark.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [4.4-8] 3cc7c8ad32 Bug #54652: wireshark 2.6.20-0+deb9u3 doc/errata/staging/wireshark.yaml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1223>