Bug 33558 - wireshark new security issue CVE-2024-8250
Summary: wireshark new security issue CVE-2024-8250
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-32-OK,MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-09-12 08:58 CEST by Nicolas Salguero
Modified: 2024-09-16 19:45 CEST (History)
4 users (show)

See Also:
Source RPM: wireshark-4.0.15-1.mga9.src.rpm
CVE: CVE-2024-8250
Status comment:


Attachments

Nicolas Salguero 2024-09-12 09:00:54 CEST

Source RPM: (none) => wireshark-4.2.6-1.mga10.src.rpm, wireshark-4.0.15-1.mga9.src.rpm
CVE: (none) => CVE-2024-8250
Status comment: (none) => Fixed upstream in 4.2.7 (for Cauldron) and 4.0.17 (for Mga9)
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2024-09-12 16:18:28 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

NTLMSSP dissector crash in Wireshark 4.2.0 to 4.2.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file. (CVE-2024-8250)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QKFBRZUBCTYT4V2V5ONIWBIEEUYHI3HD/
========================

Updated packages in core/updates_testing:
========================
dumpcap-4.0.17-1.mga9
lib(64)wireshark16-4.0.17-1.mga9
lib(64)wireshark-devel-4.0.17-1.mga9
lib(64)wiretap13-4.0.17-1.mga9
lib(64)wsutil14-4.0.17-1.mga9
rawshark-4.0.17-1.mga9
tshark-4.0.17-1.mga9
wireshark-4.0.17-1.mga9
wireshark-tools-4.0.17-1.mga9

from SRPM:
wireshark-4.0.17-1.mga9.src.rpm

Assignee: bugsquad => qa-bugs
Whiteboard: MGA9TOO => (none)
Source RPM: wireshark-4.2.6-1.mga10.src.rpm, wireshark-4.0.15-1.mga9.src.rpm => wireshark-4.0.15-1.mga9.src.rpm
Version: Cauldron => 9
Status: NEW => ASSIGNED
Status comment: Fixed upstream in 4.2.7 (for Cauldron) and 4.0.17 (for Mga9) => (none)

Comment 2 PC LX 2024-09-12 16:55:11 CEST
Installed and tested without issues.

Tested:
- packet capture;
- filters;
- saving and loading, including previous captures;
- bunch of other minor functions.

This was a quick test (don't have time for more now) but no issues were found.



System: Mageia 9, x86_64, Plasma DE, LXQt DE, AMD Ryzen 5 5600G with Radeon Graphics using amdgpu driver.



$ uname -a
Linux jupiter 6.6.50-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Sun Sep  8 12:38:27 UTC 2024 x86_64 GNU/Linux
$ rpm -qa | grep 4.0.17-1
lib64wsutil14-4.0.17-1.mga9
lib64wiretap13-4.0.17-1.mga9
lib64wireshark16-4.0.17-1.mga9
dumpcap-4.0.17-1.mga9
wireshark-4.0.17-1.mga9

CC: (none) => mageia

Comment 3 Brian Rockwell 2024-09-15 03:11:26 CEST
MGA9-32

The following 39 packages are going to be installed:

- dumpcap-4.0.17-1.mga9.i586
- libassimp5-5.2.2-4.1.mga9.i586
- libbcg729_0-1.1.1-2.mga9.i586
- liblua5.1-5.1.5-22.mga9.i586
- libpoly2tri1.0-1.0-0.20220520.1.mga9.i586
- libqt6concurrent6-6.4.1-5.mga9.i586
- libqt6core5compat6-6.4.1-3.mga9.i586
- libqt6multimedia-plugins-6.4.1-2.mga9.i586
- libqt6multimedia6-6.4.1-2.mga9.i586
- libqt6multimediaquick6-6.4.1-2.mga9.i586
- libqt6quick3d6-6.4.1-2.mga9.i586
- libqt6quick3dassetimport6-6.4.1-2.mga9.i586
- libqt6quick3dassetutils6-6.4.1-2.mga9.i586
- libqt6quick3deffects6-6.4.1-2.mga9.i586
- libqt6quick3dglslparser6-6.4.1-2.mga9.i586
- libqt6quick3dhelpers6-6.4.1-2.mga9.i586
- libqt6quick3diblbaker6-6.4.1-2.mga9.i586
- libqt6quick3dparticleeffects6-6.4.1-2.mga9.i586
- libqt6quick3dparticles6-6.4.1-2.mga9.i586
- libqt6quick3druntimerender6-6.4.1-2.mga9.i586
- libqt6quick3dspatialaudio6-6.4.1-2.mga9.i586
- libqt6quick3dutils6-6.4.1-2.mga9.i586
- libqt6quicktimeline6-6.4.1-2.mga9.i586
- libqt6shadertools6-6.4.1-2.mga9.i586
- libqt6spatialaudio6-6.4.1-2.mga9.i586
- libsmi-mibs-std-0.5.0-5.mga9.i586
- libsmi2-0.5.0-5.mga9.i586
- libstbi1-1.33-8.mga9.i586
- libwireshark16-4.0.17-1.mga9.i586
- libwiretap13-4.0.17-1.mga9.i586
- libwsutil14-4.0.17-1.mga9.i586
- qt5compat6-6.4.1-3.mga9.i586
- qtimageformats6-6.4.1-1.mga9.i586
- qtmultimedia6-6.4.1-2.mga9.i586
- qtquick3d6-6.4.1-2.mga9.i586
- qtquicktimeline6-6.4.1-2.mga9.i586
- qtshadertools6-6.4.1-2.mga9.i586
- smi-tools-0.5.0-5.mga9.i586
- wireshark-4.0.17-1.mga9.i586

147MB of additional disk space will be used.

37MB of packages will be retrieved.

--

executed wireshark from command line as root

I was able to perform captures

working for me

CC: (none) => brtians1
Whiteboard: (none) => MGA9-32-OK

katnatek 2024-09-15 19:02:36 CEST

Whiteboard: MGA9-32-OK => MGA9-32-OK,MGA9-64-OK
CC: (none) => andrewsfarm

Comment 4 Thomas Andrews 2024-09-16 02:23:48 CEST
Validating. Advisory information in Comment 1.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 5 katnatek 2024-09-16 02:50:01 CEST
(In reply to Thomas Andrews from comment #4)
> Validating. Advisory information in Comment 1.

I skip this , thank you, to remember the lack of advisory

Keywords: (none) => advisory

Comment 6 Mageia Robot 2024-09-16 19:45:41 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0303.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.