Opened 13 months ago

Closed 13 months ago

Last modified 9 months ago

#17930 closed enhancement (fixed)

wireshark-4.0.5

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.0
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Douglas R. Reno, 13 months ago

Priority: normalelevated

Contains three security fixes

comment:2 by Douglas R. Reno, 13 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:3 by Douglas R. Reno, 13 months ago

Bug Fixes

The following vulnerabilities have been fixed:

  • wnpa-sec-2023-09[3] RPCoRDMA dissector crash. Issue 18852[4]. CVE-2023-1992[5].
  • wnpa-sec-2023-10[6] LISP dissector large loop. Issue 18900[7]. CVE-2023-1993[8].
  • wnpa-sec-2023-11[9] GQUIC dissector crash Issue 18947[10]. CVE-2023-1994[11].

The following bugs have been fixed:

  • Wireshark ITS Dissector RTCMEM wrong protocol version selector 2
    • should use 1. Issue 18862[12].
  • Wireshark treats the letter E in SSRC as an exponential representation of a number. Issue 18879[13].
  • VNC RRE Parser skips over data. Issue 18883[14].
  • sshdump coredump when --remote-interface is left empty. Issue 18904[15].
  • Fuzz job crash output: fuzz-2023-03-17-7298.pcap. Issue 18917[16].
  • Fuzz job crash output: fuzz-2023-03-27-7564.pcap. Issue 18934[17].
  • RFC8925 support (dhcp option 108) Issue 18943[18].
  • DIS dissector shows an incorrect state in the packet list info column. Issue 18967[19].
  • RTP analysis shows incorrect timestamp error when timestamp is rolled over. Issue 18973[20].
  • Asterisk (*) key crash on Endpoint/Conversation dialog. Issue 18975[21].
  • The RTP player waveform now synchronizes better with audio.

comment:4 by Douglas R. Reno, 13 months ago

Resolution: fixed
Status: assignedclosed

Fixed at 746cbd8040439248e6b9702053f46d60095634c4

SA-11.3-021 issued

comment:5 by Bruce Dubbs, 9 months ago

Milestone: 11.412.0

Milestone renamed

Note: See TracTickets for help on using tickets.