Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 913030 (WNPA-SEC-2023-23, WNPA-SEC-2023-24, WNPA-SEC-2023-25, WNPA-SEC-2023-26) - <net-analyzer/wireshark-4.0.8: Multiple vulnerabilities
Summary: <net-analyzer/wireshark-4.0.8: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: WNPA-SEC-2023-23, WNPA-SEC-2023-24, WNPA-SEC-2023-25, WNPA-SEC-2023-26
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.wireshark.org/docs/relnot...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 914788
Blocks:
  Show dependency tree
 
Reported: 2023-08-26 04:16 UTC by Sam James
Modified: 2023-10-06 03:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-26 04:16:31 UTC
From https://www.wireshark.org/docs/relnotes/wireshark-4.0.8.html:

    wnpa-sec-2023-23 CBOR dissector crash. Issue 19144.

    wnpa-sec-2023-24 BT SDP dissector infinite loop. Issue 19258.

    wnpa-sec-2023-25 BT SDP dissector memory leak. Issue 19259.

    wnpa-sec-2023-26 CP2179 dissector crash. Issue 19229.
Comment 1 Larry the Git Cow gentoo-dev 2023-08-26 04:28:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=50ab85eeaf5b24fc75ccfcdaa2a139a56bbc452b

commit 50ab85eeaf5b24fc75ccfcdaa2a139a56bbc452b
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-08-26 04:20:24 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-08-26 04:20:24 +0000

    net-analyzer/wireshark: add 4.0.8
    
    Bug: https://bugs.gentoo.org/913030
    Signed-off-by: Sam James <sam@gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 +
 net-analyzer/wireshark/wireshark-4.0.8.ebuild | 316 ++++++++++++++++++++++++++
 2 files changed, 317 insertions(+)
Comment 2 Hans de Graaff gentoo-dev Security 2023-09-29 07:48:42 UTC
GLSA vote: no.
Comment 3 Larry the Git Cow gentoo-dev 2023-10-06 00:32:11 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1c1d3276ca171da1934fcd62618dbdc9d9afe173

commit 1c1d3276ca171da1934fcd62618dbdc9d9afe173
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2023-10-05 23:59:11 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-10-05 23:59:11 +0000

    net-analyzer/wireshark: drop 4.0.6, 4.0.7
    
    Bug: https://bugs.gentoo.org/913030
    Bug: https://bugs.gentoo.org/910333
    Signed-off-by: Sam James <sam@gentoo.org>

 net-analyzer/wireshark/Manifest               |   2 -
 net-analyzer/wireshark/wireshark-4.0.6.ebuild | 316 --------------------------
 net-analyzer/wireshark/wireshark-4.0.7.ebuild | 316 --------------------------
 3 files changed, 634 deletions(-)