| Summary: | wireshark new release 2.2.10 fixes security issues | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | davidwhodgins, digidietze, sysadmin-bugs, wilcal.int |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | has_procedure, MGA6-32-OK MGA6-64-OK | ||
| Source RPM: | wireshark-2.2.9-1.mga6.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2017-10-12 13:35:50 CEST
Testing procedure: https://wiki.mageia.org/en/QA_procedure:Wireshark Whiteboard:
(none) =>
has_procedure VE-2017-15191 (DMP dissector crash) ==================================== Test (POC from related upstream bug 14068): > tshark -Vxr clusterfuzz-testcase-minimized-4674256493346816.pcap Pre-Update on MGA6-x86_64 (lib64wireshark8-2.2.9-1.mga6): No obvious problem Post-Update on MGA6-x86_64: (lib64wireshark8-2.2.10-1.mga6) No obvious problem CVE-2017-15192 (BT ATT dissector crash) ======================================= Test (POC from related upstream bug 14049) > tshark -Vxr clusterfuzz-testcase-minimized-4559062802890752.pcap Pre-Update on MGA6-x86_64 (lib64wireshark8-2.2.9-1.mga6): Segfault/Core dump Post-Update on MGA6-x86_64 (lib64wireshark8-2.2.10-1.mga6) No obvious problem CVE-2017-15193 (MBIM dissector crash) ===================================== Test (POC from related upstream bug 14056) > tshark -Vxr fuzz-2017-09-10-28159.pcap Pre-Update on MGA6-x86_64 (lib64wireshark8-2.2.9-1.mga6): No obvious problem Post-Update on MGA6-x86_64: (lib64wireshark8-2.2.10-1.mga6) No obvious problem CC:
(none) =>
digidietze In VirtualBox, M6, Plasma, 32-bit Package(s) under test: wireshark libwireshark8 libwiretap6 libwsutil7 wireshark-tools tshark Assign wilcal to the wireshark group, restart wilcal. default install of : [root@localhost wilcal]# urpmi wireshark Package wireshark-2.2.9-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwireshark8 Package libwireshark8-2.2.9-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwiretap6 Package libwiretap6-2.2.9-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwsutil7 Package libwsutil7-2.2.9-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi wireshark-tools Package wireshark-tools-2.2.9-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi tshark Package tshark-2.2.9-1.mga6.i586 is already installed Running wireshark I can capture and save to a file (test01.pcapng) the traffic on enp0s3. Close wireshark. I can reopen test01.pcapng with wireshark and review the data. wireshark tools like tshark work: tshark >> test01.txt works Capturing on 'enp0s3' 5508 ^Z ( captured lines ) [1]+ Stopped tshark >> test01.txt Set a filter: ip.src == 192.168.1.65 ( this system ) ip.addr == 192.168.1.70 ( Yamaha receiver ) Set filter to: not ip.addr == 192.168.1.65 and not ip.src == 192.168.1.70 Filter works. install wireshark libwireshark7 libwiretap5 libwsutil6 wireshark-tools tshark from updates_testing [root@localhost wilcal]# urpmi wireshark Package wireshark-2.2.10-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwireshark8 Package libwireshark8-2.2.10-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwiretap6 Package libwiretap6-2.2.10-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi libwsutil7 Package libwsutil7-2.2.10-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi wireshark-tools Package wireshark-tools-2.2.10-1.mga6.i586 is already installed [root@localhost wilcal]# urpmi tshark Package tshark-2.2.10-1.mga6.i586 is already installed Running wireshark I can capture and save to a file (test02.pcapng) the traffic on enp0s3. Close wireshark. Reopen test01.pcapng & test02.pcapng with wireshark and review the data. wireshark tools like tshark work: tshark >> test02.txt works Capturing on 'enp0s3' 3878 ^Z ( captured lines ) [1]+ Stopped tshark >> test02.txt Set a filter: ip.src == 192.168.1.65 ( this system ) ip.addr == 192.168.1.70 ( Yamaha receiver ) Set filter to: not ip.addr == 192.168.1.65 and not ip.src == 192.168.1.70 Filter works. CC:
(none) =>
wilcal.int
William Kenney
2017-10-14 01:58:14 CEST
Whiteboard:
has_procedure, MGA6-64-OK =>
has_procedure, MGA6-32-OK MGA6-64-OK This update works fine. Testing complete for MGA6, 32-bit & 64-bit Validating the update. Could someone from the sysadmin team push to updates. Thanks Keywords:
(none) =>
validated_update
Dave Hodgins
2017-10-18 06:29:56 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2017-0374.html Status:
NEW =>
RESOLVED |