Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 724132 (CVE-2020-13164, wnpa-sec-2020-08) - <net-analyzer/wireshark-3.2.4 - The NFS dissector could crash (CVE-2020-13164)
Summary: <net-analyzer/wireshark-3.2.4 - The NFS dissector could crash (CVE-2020-13164)
Status: RESOLVED FIXED
Alias: CVE-2020-13164, wnpa-sec-2020-08
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.wireshark.org/security/wn...
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on: CVE-2020-15466
Blocks: CVE-2020-9428, CVE-2020-9429, CVE-2020-9430, CVE-2020-9431 CVE-2020-11647, wnpa-sec-2020-07
  Show dependency tree
 
Reported: 2020-05-19 20:32 UTC by Sam James
Modified: 2020-07-26 23:49 UTC (History)
2 users (show)

See Also:
Package list:
=net-analyzer/wireshark-3.2.4
Runtime testing required: ---
nattka: sanity-check-


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-19 20:32:21 UTC
Description:
"The NFS dissector could crash"

Fixed in 3.2.4.
Comment 1 Larry the Git Cow gentoo-dev 2020-05-19 21:08:12 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c28b73feb8531f724b67b5b2eb4ca118b669a704

commit c28b73feb8531f724b67b5b2eb4ca118b669a704
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-05-19 21:03:32 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-05-19 21:08:08 +0000

    net-analyzer/wireshark: Version 3.2.4
    
    Package-Manager: Portage-2.3.99, Repoman-2.3.22
    Bug: https://bugs.gentoo.org/show_bug.cgi?id=724132
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 +
 net-analyzer/wireshark/wireshark-3.2.4.ebuild | 254 ++++++++++++++++++++++++++
 2 files changed, 255 insertions(+)
Comment 2 NATTkA bot gentoo-dev 2020-05-19 21:08:43 UTC
Unable to check for sanity:

> no match for package: =net-analyzer/wireshark-3.2.4
Comment 3 NATTkA bot gentoo-dev 2020-05-19 21:12:44 UTC
All sanity-check issues have been resolved
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-19 23:11:44 UTC
"It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file."
Comment 5 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2020-05-25 12:20:23 UTC
amd64 stable
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-06-19 06:43:20 UTC
ARM, PPC64, x86?
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2020-06-20 13:51:10 UTC
x86 stable
Comment 8 ernsteiswuerfel archtester 2020-06-20 22:16:41 UTC
ppc64 fails 4 tests (bug #728950).
Comment 9 Agostino Sarubbo gentoo-dev 2020-06-21 17:00:25 UTC
arm stable
Comment 10 Agostino Sarubbo gentoo-dev 2020-06-21 17:10:52 UTC
ppc64 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 11 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-22 20:47:03 UTC
(In reply to Agostino Sarubbo from comment #10)
> ppc64 stable.
> 
> Maintainer(s), please cleanup.
> Security, please vote.

Cleanup was done in https://gitweb.gentoo.org/repo/gentoo.git/commit/net-analyzer/wireshark?id=3b5465d0f2beddc7805bf550262a145fd087a275.
Comment 12 NATTkA bot gentoo-dev 2020-07-05 14:04:55 UTC
Unable to check for sanity:

> no match for package: =net-analyzer/wireshark-3.2.4
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2020-07-26 23:49:53 UTC
This issue was resolved and addressed in
 GLSA 202007-13 at https://security.gentoo.org/glsa/202007-13
by GLSA coordinator Sam James (sam_c).