Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 736914 (CVE-2020-17498, wnpa-sec-2020-10) - <net-analyzer/wireshark-3.2.6 - Kafka dissector crash (CVE-2020-17498)
Summary: <net-analyzer/wireshark-3.2.6 - Kafka dissector crash (CVE-2020-17498)
Status: RESOLVED FIXED
Alias: CVE-2020-17498, wnpa-sec-2020-10
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://www.wireshark.org/lists/wires...
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-08-12 20:05 UTC by Jeroen Roovers (RETIRED)
Modified: 2020-09-23 13:42 UTC (History)
2 users (show)

See Also:
Package list:
=net-analyzer/wireshark-3.2.6
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2020-08-12 20:05:39 UTC
wnpa-sec-2020-10[1] Kafka dissector crash. Bug 16672[2]. CVE-2020-17498[3].
Comment 1 Larry the Git Cow gentoo-dev 2020-08-12 20:08:00 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=87e098dcd8ae94957d4aa2cb3703e5129a1d6602

commit 87e098dcd8ae94957d4aa2cb3703e5129a1d6602
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-08-12 20:07:36 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-08-12 20:07:56 +0000

    net-analyzer/wireshark: Version 3.2.6
    
    Package-Manager: Portage-3.0.2, Repoman-2.3.23
    Bug: https://bugs.gentoo.org/736914
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 +
 net-analyzer/wireshark/wireshark-3.2.6.ebuild | 261 ++++++++++++++++++++++++++
 2 files changed, 262 insertions(+)
Comment 2 NATTkA bot gentoo-dev 2020-08-12 20:08:31 UTC
Unable to check for sanity:

> no match for package: =net-analyzer/wireshark-3.2.6
Comment 3 NATTkA bot gentoo-dev 2020-08-12 20:12:34 UTC
All sanity-check issues have been resolved
Comment 4 Sam James archtester gentoo-dev Security 2020-08-14 21:53:48 UTC
amd64 done
Comment 5 Sam James archtester gentoo-dev Security 2020-08-15 00:19:58 UTC
arm done
Comment 6 Agostino Sarubbo gentoo-dev 2020-08-17 07:10:31 UTC
x86 stable
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2020-08-26 21:43:57 UTC
This issue was resolved and addressed in
 GLSA 202008-14 at https://security.gentoo.org/glsa/202008-14
by GLSA coordinator Sam James (sam_c).
Comment 8 Sam James archtester gentoo-dev Security 2020-08-26 21:45:06 UTC
Reopening for ppc64.
Comment 9 John Helmert III (ajak) gentoo-dev Security 2020-09-20 16:22:25 UTC
ppc64: ping
Comment 10 Agostino Sarubbo gentoo-dev 2020-09-23 10:30:34 UTC
ppc64 stable.

Maintainer(s), please cleanup.
Comment 11 Larry the Git Cow gentoo-dev 2020-09-23 13:41:23 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=95c14f68a5860abf638ff6d1f6605211e84a4690

commit 95c14f68a5860abf638ff6d1f6605211e84a4690
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-09-23 13:41:00 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-09-23 13:41:21 +0000

    net-analyzer/wireshark: Old
    
    Package-Manager: Portage-3.0.8, Repoman-3.0.1
    Bug: https://bugs.gentoo.org/show_bug.cgi?id=736914
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 -
 net-analyzer/wireshark/wireshark-3.2.5.ebuild | 261 --------------------------
 2 files changed, 262 deletions(-)