Bug 965112 (CVE-2013-3562)
| Summary: | CVE-2013-3562 wireshark: DoS (stack overflow, crash) in the Websocket dissector (wnpa-sec-2013-29, upstream #8448, #8499) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | huzaifas, jrusnack, jsafrane, phatina, rvokal |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-05-21 06:45:16 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 965942, 979246 | ||
| Bug Blocks: | 965198 | ||
|
Description
Jan Lieskovsky
2013-05-20 12:58:47 UTC
Upstream advisory: http://www.wireshark.org/security/wnpa-sec-2013-29.html The version of wireshark shipped with Red Hat Enterprise Linux 5 and 6 does not have support for parsing Websocket data. Statement: Not Vulnerable. This issue does not affect the version of wireshark as shipped with Red Hat Enterprise Linux 5 and 6. Created wireshark tracking bugs for this issue Affects: fedora-18 [bug 965942] As per http://seclists.org/oss-sec/2013/q2/378 , this issue has been split into two CVEs, the following explanation has been given by MITRE: "Use CVE-2013-3561 for the Bug 8448 issue. Note that this CVE is shared with issues covered by wnpa-sec-2013-30 and wnpa-sec-2013-31. Use CVE-2013-3562 for the Bug 8449 issue." This bug is being used for CVE-2013-3562. CVE-2013-3561 will be filed separately. wireshark-1.10.2-6.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. wireshark-1.10.2-7.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. wireshark-1.10.2-4.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report. |