GLSA 201604-05: Wireshark: Multiple vulnerabilities
Severity: | normal |
Title: | Wireshark: Multiple vulnerabilities |
Date: | 04/26/2016 |
Bugs: |
|
ID: | 201604-05 |
Synopsis
Multiple vulnerabilities have been found in Wireshark, allowing local attackers to escalate privileges and remote attackers to cause Denial of Service.Background
Wireshark is a network protocol analyzer formerly known as ethereal.
Affected packages
Package | Vulnerable | Unaffected | Architecture(s) |
---|---|---|---|
net-analyzer/wireshark | < 2.0.2 | >= 2.0.2 | All supported architectures |
Description
Multiple vulnerabilities have been discovered in Wireshark. Please review the CVE identifiers referenced below for details.
Impact
Remote attackers could cause Denial of Service and local attackers could escalate privileges.
Workaround
There is no known workaround at this time.
Resolution
All Wireshark users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-2.0.2"
References
CVE-2015-8711 CVE-2015-8712 CVE-2015-8713 CVE-2015-8714 CVE-2015-8715 CVE-2015-8716 CVE-2015-8717 CVE-2015-8718 CVE-2015-8719 CVE-2015-8720 CVE-2015-8721 CVE-2015-8722 CVE-2015-8723 CVE-2015-8724 CVE-2015-8725 CVE-2015-8726 CVE-2015-8727 CVE-2015-8728 CVE-2015-8729 CVE-2015-8730 CVE-2015-8731 CVE-2015-8732 CVE-2015-8733 CVE-2015-8734 CVE-2015-8735 CVE-2015-8736 CVE-2015-8737 CVE-2015-8738 CVE-2015-8739 CVE-2015-8740 CVE-2015-8741 CVE-2015-8742 CVE-2016-2521 CVE-2016-2522 CVE-2016-2523 CVE-2016-2524 CVE-2016-2525 CVE-2016-2526 CVE-2016-2527 CVE-2016-2528 CVE-2016-2529 CVE-2016-2530 CVE-2016-2531 CVE-2016-2532
Availability
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.
License
Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.