Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 750692 (CVE-2020-26575) - <net-analyzer/wireshark-3.4.0_rc1: Multiple vulnerabilities (CVE-2020-26575)
Summary: <net-analyzer/wireshark-3.4.0_rc1: Multiple vulnerabilities (CVE-2020-26575)
Status: RESOLVED FIXED
Alias: CVE-2020-26575
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://gitlab.com/wireshark/wireshar...
Whiteboard: A3 [glsa+ cve]
Keywords: CC-ARCHES
Depends on: 751358
Blocks:
  Show dependency tree
 
Reported: 2020-10-22 00:58 UTC by John Helmert III
Modified: 2020-11-16 06:11 UTC (History)
3 users (show)

See Also:
Package list:
net-analyzer/wireshark-3.4.0 media-libs/bcg729-1.0.4-r1
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III gentoo-dev Security 2020-10-22 00:58:23 UTC
CVE-2020-26575:

In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.


Patch at $URL. I don't actually see that commit in any release, so I suspect the CVE description is wrong.
Comment 1 John Helmert III gentoo-dev Security 2020-10-25 02:27:08 UTC
Patch is in 3.4.0rc1 so will modify summary but it's likely not a good stable candidate so will leave at [ebuild].
Comment 2 Larry the Git Cow gentoo-dev 2020-10-29 22:09:42 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fa6c736f85d46e3b77b0dca1213025d208517a94

commit fa6c736f85d46e3b77b0dca1213025d208517a94
Author:     David Seifert <soap@gentoo.org>
AuthorDate: 2020-10-29 22:09:16 +0000
Commit:     David Seifert <soap@gentoo.org>
CommitDate: 2020-10-29 22:09:16 +0000

    net-analyzer/wireshark: Remove old 3.4.0_rc1
    
    Bug: https://bugs.gentoo.org/750692
    Package-Manager: Portage-3.0.8, Repoman-3.0.2
    Signed-off-by: David Seifert <soap@gentoo.org>

 net-analyzer/wireshark/Manifest                   |   1 -
 net-analyzer/wireshark/wireshark-3.4.0_rc1.ebuild | 259 ----------------------
 2 files changed, 260 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7e870cc59a011d588b0f932c565bab52021a0b59

commit 7e870cc59a011d588b0f932c565bab52021a0b59
Author:     David Seifert <soap@gentoo.org>
AuthorDate: 2020-10-29 22:09:13 +0000
Commit:     David Seifert <soap@gentoo.org>
CommitDate: 2020-10-29 22:09:13 +0000

    net-analyzer/wireshark: Version bump to 3.4.0
    
    Bug: https://bugs.gentoo.org/750692
    Package-Manager: Portage-3.0.8, Repoman-3.0.2
    Signed-off-by: David Seifert <soap@gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 +
 net-analyzer/wireshark/wireshark-3.4.0.ebuild | 259 ++++++++++++++++++++++++++
 2 files changed, 260 insertions(+)
Comment 3 NATTkA bot gentoo-dev 2020-11-02 12:28:54 UTC
Sanity check failed:

> net-analyzer/wireshark-3.4.0
>   depend arm64 stable profile default/linux/arm64/17.0 (9 total)
>     media-libs/bcg729
>   rdepend arm64 stable profile default/linux/arm64/17.0 (9 total)
>     media-libs/bcg729
Comment 4 Sam James archtester gentoo-dev Security 2020-11-04 01:48:35 UTC
arm64 done
Comment 5 Sam James archtester gentoo-dev Security 2020-11-04 09:23:25 UTC
arm done
Comment 6 Sam James archtester gentoo-dev Security 2020-11-06 20:26:46 UTC
amd64 stable
Comment 7 Sam James archtester gentoo-dev Security 2020-11-06 21:43:47 UTC
ppc64 stable
Comment 8 Sam James archtester gentoo-dev Security 2020-11-08 10:22:27 UTC
x86 done

all arches done
Comment 9 NATTkA bot gentoo-dev 2020-11-08 10:24:58 UTC
Resetting sanity check; keywords are not fully specified and arches are not CC-ed.
Comment 10 Sam James archtester gentoo-dev Security 2020-11-09 20:53:44 UTC
wnpa-sec-2020-15 

Description:

The GQUIC protocol dissector could crash.

Impact:
It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2020-11-11 03:49:59 UTC
This issue was resolved and addressed in
 GLSA 202011-08 at https://security.gentoo.org/glsa/202011-08
by GLSA coordinator Sam James (sam_c).
Comment 12 Larry the Git Cow gentoo-dev 2020-11-16 06:10:49 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=cf1f049003feaf74580f26c50ad6a91c35056d8e

commit cf1f049003feaf74580f26c50ad6a91c35056d8e
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2020-11-16 06:10:41 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2020-11-16 06:10:41 +0000

    net-analyzer/wireshark: security cleanup
    
    Bug: https://bugs.gentoo.org/750692
    Package-Manager: Portage-3.0.8, Repoman-3.0.2
    Signed-off-by: Sam James <sam@gentoo.org>

 net-analyzer/wireshark/Manifest                    |   1 -
 .../files/wireshark-2.4-androiddump.patch          |  27 ---
 .../files/wireshark-2.9.0-tfshark-libm.patch       |  10 -
 .../wireshark-99999999-androiddump-wsutil.patch    |  19 --
 .../wireshark/files/wireshark-99999999-qtsvg.patch |  10 -
 net-analyzer/wireshark/wireshark-3.2.7-r1.ebuild   | 256 ---------------------
 6 files changed, 323 deletions(-)