MGASA-2020-0384 - Updated wireshark packages fix security vulnerabilities

Publication date: 16 Oct 2020
URL: https://advisories.mageia.org/MGASA-2020-0384.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-25862,
     CVE-2020-25863,
     CVE-2020-25866

The TCP dissector could crash (CVE-2020-25862).

The MIME Multipart dissector could crash (CVE-2020-25863).

The BLIP dissector could crash (CVE-2020-25866).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27397
- https://www.wireshark.org/security/wnpa-sec-2020-11
- https://www.wireshark.org/security/wnpa-sec-2020-12
- https://www.wireshark.org/security/wnpa-sec-2020-13
- https://www.wireshark.org/docs/relnotes/wireshark-3.0.14.html
- https://www.wireshark.org/news/20200923.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25862
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25863
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25866

SRPMS:
- 7/core/wireshark-3.0.14-1.mga7

Mageia 2020-0384: wireshark security update

The TCP dissector could crash (CVE-2020-25862)

Summary

The TCP dissector could crash (CVE-2020-25862).
The MIME Multipart dissector could crash (CVE-2020-25863).
The BLIP dissector could crash (CVE-2020-25866).

References

- https://bugs.mageia.org/show_bug.cgi?id=27397

- https://www.wireshark.org/security/wnpa-sec-2020-11

- https://www.wireshark.org/security/wnpa-sec-2020-12

- https://www.wireshark.org/security/wnpa-sec-2020-13

- https://www.wireshark.org/docs/relnotes/wireshark-3.0.14.html

- https://www.wireshark.org/news/20200923.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25862

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25863

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25866

Resolution

MGASA-2020-0384 - Updated wireshark packages fix security vulnerabilities

SRPMS

- 7/core/wireshark-3.0.14-1.mga7

Severity
Publication date: 16 Oct 2020
URL: https://advisories.mageia.org/MGASA-2020-0384.html
Type: security
CVE: CVE-2020-25862, CVE-2020-25863, CVE-2020-25866

Related News