ALINUX2-SA-2020%3A0078
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-11362: In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character. CVE-2018-14340: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read. CVE-2018-14341: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow. CVE-2018-14368: In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the Bazaar protocol dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by properly handling items that are too long. CVE-2018-16057: In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations. CVE-2018-19622: In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the MMSE dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-mmse.c by preventing length overflows. CVE-2018-7418: In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | wireshark |
Timeline
- Apr 3, 2020 CVE Updated
- Apr 4, 2020 CVE Published
References
- ALINUX2-SA-2020:0078: wireshark security and bug fix update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11362 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14340 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14341 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14368 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16057 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19622 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7418 advisory