CVE-2015-2187 CVE-2015-2188 CVE-2015-2189 CVE-2015-2190 CVE-2015-2191 CVE-2015-2192

Related Vulnerabilities: CVE-2015-2187   CVE-2015-2188   CVE-2015-2189   CVE-2015-2190   CVE-2015-2191   CVE-2015-2192   CVE-2015-0562   CVE-2015-0564   CVE-2014-8710   CVE-2014-8711   CVE-2014-8712   CVE-2014-8713   CVE-2014-8714   CVE-2014-6422   CVE-2014-6423   CVE-2014-6424   CVE-2014-6427   CVE-2014-6428   CVE-2014-6429   CVE-2014-6430   CVE-2014-6431   CVE-2014-6432   CVE-2014-5161   CVE-2014-5162   CVE-2014-5163   CVE-2014-5164   CVE-2014-5165   CVE-2014-2281   CVE-2014-2283   CVE-2014-2299   CVE-2013-7113   CVE-2013-7114   CVE-2013-6336   CVE-2013-6337   CVE-2013-6338   CVE-2013-6340   CVE-2013-4930   CVE-2013-4932   CVE-2013-4933   CVE-2013-4934   CVE-2013-4935   CVE-2013-4074   CVE-2013-4075   CVE-2013-4076   CVE-2013-4077   CVE-2013-4078   CVE-2013-4081   CVE-2013-4082   CVE-2013-4083   CVE-2013-3555   CVE-2013-3557   CVE-2013-3558   CVE-2013-3559   CVE-2013-3560   CVE-2013-3562   CVE-2013-2475   CVE-2013-2477   CVE-2013-2478   CVE-2013-2480   CVE-2013-2481   CVE-2013-2483   CVE-2013-2484   CVE-2013-2488   CVE-2013-1582   CVE-2013-1583   CVE-2013-1584   CVE-2013-1585   CVE-2013-1586   CVE-2013-1587   CVE-2013-1588   CVE-2013-1590   CVE-2012-5237   CVE-2012-5238   CVE-2012-5239   CVE-2012-5240   CVE-2012-4048   CVE-2012-4049   CVE-2012-4285   CVE-2012-4287   CVE-2012-4288   CVE-2012-4294   CVE-2012-4295   CVE-2012-4289   CVE-2012-4296   CVE-2012-4297   CVE-2012-4291   CVE-2012-4292   CVE-2012-4293   CVE-2012-4290   CVE-2012-4286   CVE-2012-4298   CVE-2011-3484   CVE-2011-3266   CVE-2011-3483   CVE-2011-3360   CVE-2011-3482   CVE-2011-2597   CVE-2010-4538   CVE-2010-3445  

Debian Bug report logs - #780372
CVE-2015-2187 CVE-2015-2188 CVE-2015-2189 CVE-2015-2190 CVE-2015-2191 CVE-2015-2192

version graph

Reported by: Moritz Muehlenhoff <jmm@debian.org>

Date: Thu, 12 Mar 2015 21:33:01 UTC

Severity: important

Tags: security, upstream

Fixed in versions wireshark/1.12.1+g01b65bf-4, wireshark/1.8.2-5wheezy15, wireshark/1.8.2-5wheezy15~deb6u1

Done: Balint Reczey <balint@balintreczey.hu>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Balint Reczey <balint@balintreczey.hu>:
Bug#780372; Package wireshark. (Thu, 12 Mar 2015 21:33:06 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <jmm@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Balint Reczey <balint@balintreczey.hu>. (Thu, 12 Mar 2015 21:33:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <jmm@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2015-2187 CVE-2015-2188 CVE-2015-2189 CVE-2015-2190 CVE-2015-2191 CVE-2015-2192
Date: Thu, 12 Mar 2015 22:28:39 +0100
Package: wireshark
Severity: important
Tags: security

Please see
https://security-tracker.debian.org/tracker/CVE-2015-2187
https://security-tracker.debian.org/tracker/CVE-2015-2188
https://security-tracker.debian.org/tracker/CVE-2015-2189
https://security-tracker.debian.org/tracker/CVE-2015-2190
https://security-tracker.debian.org/tracker/CVE-2015-2191
https://security-tracker.debian.org/tracker/CVE-2015-2192

Cheers,
        Moritz



Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 12 Mar 2015 22:21:05 GMT) (full text, mbox, link).


Reply sent to Balint Reczey <balint@balintreczey.hu>:
You have taken responsibility. (Thu, 26 Mar 2015 19:21:06 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Thu, 26 Mar 2015 19:21:06 GMT) (full text, mbox, link).


Message #12 received at 780372-close@bugs.debian.org (full text, mbox, reply):

From: Balint Reczey <balint@balintreczey.hu>
To: 780372-close@bugs.debian.org
Subject: Bug#780372: fixed in wireshark 1.12.1+g01b65bf-4
Date: Thu, 26 Mar 2015 19:19:20 +0000
Source: wireshark
Source-Version: 1.12.1+g01b65bf-4

We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 780372@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Balint Reczey <balint@balintreczey.hu> (supplier of updated wireshark package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 26 Mar 2015 19:15:54 +0100
Source: wireshark
Binary: wireshark-common wireshark wireshark-qt tshark wireshark-dev wireshark-dbg wireshark-doc libwireshark5 libwsutil4 libwsutil-dev libwireshark-data libwireshark-dev libwiretap4 libwiretap-dev
Architecture: source i386 all
Version: 1.12.1+g01b65bf-4
Distribution: unstable
Urgency: high
Maintainer: Balint Reczey <balint@balintreczey.hu>
Changed-By: Balint Reczey <balint@balintreczey.hu>
Description:
 libwireshark-data - network packet dissection library -- data files
 libwireshark-dev - network packet dissection library -- development files
 libwireshark5 - network packet dissection library -- shared library
 libwiretap-dev - network packet capture library -- development files
 libwiretap4 - network packet capture library -- shared library
 libwsutil-dev - network packet dissection utilities library -- shared library
 libwsutil4 - network packet dissection utilities library -- shared library
 tshark     - network traffic analyzer - console version
 wireshark  - network traffic analyzer - GTK+ version
 wireshark-common - network traffic analyzer - common files
 wireshark-dbg - network traffic analyzer - debug symbols
 wireshark-dev - network traffic analyzer - development tools
 wireshark-doc - network traffic analyzer - documentation
 wireshark-qt - network traffic analyzer - Qt version
Closes: 780372 780596
Changes:
 wireshark (1.12.1+g01b65bf-4) unstable; urgency=high
 .
   * security fixes from Wireshark 1.12.4 (Closes: #780372):
     - The ATN-CPDLC dissector could crash (CVE-2015-2187)
     - The WCP dissector could crash (CVE-2015-2188)
     - The pcapng file parser could crash (CVE-2015-2189)
     - The LLDP dissector could crash (CVE-2015-2190)
     - The TNEF dissector could go into an infinite loop.
       Discovered by Vlad Tsyrklevich. (CVE-2015-2191)
     - The SCSI OSD dissector could go into an infinite loop.
       Discovered by Vlad Tsyrklevich. (CVE-2015-2192)
   * Fix control combos such as ctrl-a, ctrl-c in filter textbox
     (Closes: #780596)
Checksums-Sha1:
 8f9fabf9132373d62ca33c20d562a18ceb8b6e7a 3295 wireshark_1.12.1+g01b65bf-4.dsc
 34f97c14268d37d8497873894b6a3d271010890c 73972 wireshark_1.12.1+g01b65bf-4.debian.tar.xz
 71d780c4e049b75d679a91dac0d0cd5ac5d66ec4 182778 wireshark-common_1.12.1+g01b65bf-4_i386.deb
 6b4dac8df792629bebcf2a833866695cc7c893a5 843378 wireshark_1.12.1+g01b65bf-4_i386.deb
 9b42472a4b05a75e6ab3b854976db7c30730d803 1101512 wireshark-qt_1.12.1+g01b65bf-4_i386.deb
 1ac8638650d2d72bf7caa4004954623227f30154 170224 tshark_1.12.1+g01b65bf-4_i386.deb
 735aeef071741cad92f45d76665cde49ab02ab62 144574 wireshark-dev_1.12.1+g01b65bf-4_i386.deb
 c332d0312dd5d08903ea3effa2dc01a6c170f933 32997724 wireshark-dbg_1.12.1+g01b65bf-4_i386.deb
 3a12d2e272adb4805d1604c81d1442db778b77b7 3868716 wireshark-doc_1.12.1+g01b65bf-4_all.deb
 d5e28aa998f2d7e8c8c9418ea2b6d8580a486562 9625070 libwireshark5_1.12.1+g01b65bf-4_i386.deb
 9223936fe5bb5e18d20d8759701188e10cdf5714 97046 libwsutil4_1.12.1+g01b65bf-4_i386.deb
 4f66cfae242593edda0bd3f36c857dcd25d48886 71448 libwsutil-dev_1.12.1+g01b65bf-4_i386.deb
 fdd5d38781d975b59f06e6b254b5c40476e751e3 837256 libwireshark-data_1.12.1+g01b65bf-4_all.deb
 7351752c1b03f19e6c128b9d019c9ce31b550984 766824 libwireshark-dev_1.12.1+g01b65bf-4_i386.deb
 7ac8fb1b7be17ed569c8975e10702187be225b59 198766 libwiretap4_1.12.1+g01b65bf-4_i386.deb
 a698179068077a04da74326c7252f784de16515a 78522 libwiretap-dev_1.12.1+g01b65bf-4_i386.deb
Checksums-Sha256:
 b7a92d1dea80697dc159abc36c56a0230ef326ebf156242b781d206a8ce40bd4 3295 wireshark_1.12.1+g01b65bf-4.dsc
 e2af7d4f5b1092f4a31ff6963fa15b0f0d8132ee09a69e8aa807705605018e1d 73972 wireshark_1.12.1+g01b65bf-4.debian.tar.xz
 7df89d5d97b8dbc8cfc00cbae021f3cbd87b2eb602230a64ff78a7cf5fe309a8 182778 wireshark-common_1.12.1+g01b65bf-4_i386.deb
 70156777c94bea38a4a56be420c8d633f7590f1bb00e54f52589a7baad78c37b 843378 wireshark_1.12.1+g01b65bf-4_i386.deb
 9e74463faeec24112985ee15af2484fe2743bbc883f37f4cb24c69194513f47c 1101512 wireshark-qt_1.12.1+g01b65bf-4_i386.deb
 a362175887de024c2da8d16180f04effad8d0aafe65bb24f9162ababcefc7ed4 170224 tshark_1.12.1+g01b65bf-4_i386.deb
 c3dbdc78ad56321ceee25dae7bbcce964fe4fb40baf3ab0925d79f6b4caa3da2 144574 wireshark-dev_1.12.1+g01b65bf-4_i386.deb
 172249515c4623330df2e844a56cd39b01f1ddff3df96532dfb6732e38297e86 32997724 wireshark-dbg_1.12.1+g01b65bf-4_i386.deb
 6bf097bb50adb2d0509fd20b8ab6f3acbf6e635103ac9710b01e9c2bf152ee64 3868716 wireshark-doc_1.12.1+g01b65bf-4_all.deb
 a3cb4ce8a32965a0464b808fac61b4610ed664b9e0d58d2bae23ea78dfacecf2 9625070 libwireshark5_1.12.1+g01b65bf-4_i386.deb
 88fb61a24790bbe088308bd457e8c63954e6f8c566665101c3143fd7c5871294 97046 libwsutil4_1.12.1+g01b65bf-4_i386.deb
 278487c75c62cc9d7e5a8266c9584d0078d000d131ed52eb9723c91a8e4c6058 71448 libwsutil-dev_1.12.1+g01b65bf-4_i386.deb
 d473fdd404f25bd2f37c47efc0b7d6fa7823881270a87906d468a64f179fdfa0 837256 libwireshark-data_1.12.1+g01b65bf-4_all.deb
 72a53a7c3417dbea067c89ace8c6c36c1ab741bf9ec31b25901984daebeaa67b 766824 libwireshark-dev_1.12.1+g01b65bf-4_i386.deb
 00875584fa834f4e9413f5ba296d624d9a3e07cd74c068841b4d01c9034431be 198766 libwiretap4_1.12.1+g01b65bf-4_i386.deb
 af5aaddac6a4b1c340ed09883aa6c4c72eb494d5be88d906f083bd4a9f8d0642 78522 libwiretap-dev_1.12.1+g01b65bf-4_i386.deb
Files:
 8f6bac4895fa288878cb12eb7f3fa80e 3295 net optional wireshark_1.12.1+g01b65bf-4.dsc
 46265d5e8acb116c543d6f165501a329 73972 net optional wireshark_1.12.1+g01b65bf-4.debian.tar.xz
 ae5ba7c10eb114536eb1282748e0ddaa 182778 net optional wireshark-common_1.12.1+g01b65bf-4_i386.deb
 30f4474e5decfda8aac03e0c5babb1ac 843378 net optional wireshark_1.12.1+g01b65bf-4_i386.deb
 c043802bfbd613b6a7ed38eea86867a0 1101512 net optional wireshark-qt_1.12.1+g01b65bf-4_i386.deb
 6c159310bb4a2526a7a9f2d9e0565491 170224 net optional tshark_1.12.1+g01b65bf-4_i386.deb
 dbe216a671d1c425ba882f9c590932b4 144574 devel optional wireshark-dev_1.12.1+g01b65bf-4_i386.deb
 8e3d45538138b20f79201679fb99c1fe 32997724 debug extra wireshark-dbg_1.12.1+g01b65bf-4_i386.deb
 390c514e26f0c65c84e38a7b5a73ce19 3868716 doc extra wireshark-doc_1.12.1+g01b65bf-4_all.deb
 530e4fa85c4677669d57fa57780172b9 9625070 libs optional libwireshark5_1.12.1+g01b65bf-4_i386.deb
 44c79002776a59e34c0a1c44f5d278de 97046 libs optional libwsutil4_1.12.1+g01b65bf-4_i386.deb
 54b2c9b8b6c416d0ccc3fbb5d6aa110d 71448 libdevel optional libwsutil-dev_1.12.1+g01b65bf-4_i386.deb
 b2ad055c3e763234320f0540a4432503 837256 libs optional libwireshark-data_1.12.1+g01b65bf-4_all.deb
 99f044b342b9fd69721912d9f41329f0 766824 libdevel optional libwireshark-dev_1.12.1+g01b65bf-4_i386.deb
 afa868031c81f39ac0a9fe012529cf64 198766 libs optional libwiretap4_1.12.1+g01b65bf-4_i386.deb
 1bbcfc5af9f00bd6363223f3e39f0401 78522 libdevel optional libwiretap-dev_1.12.1+g01b65bf-4_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVFFYGAAoJEPZk0la0aRp9ZEkP/1jCYy6LGE9Ud7C+iQI9f9Sc
pcBY9x1NJo+qz5vSXplAg0YTtt8sLZyMwiEc6i+eO0DxIva8xwL3YVPA5XGoHilU
/AJIIfSbd/aq3e3ZKdbcmxxLF1HULWrfU3bZmyuOZUzkboG4SceH1LXb8NhMColS
xBkZ76oxf1RXhrANtsBT3NFfK7QkMp8ELYbkkSfwAcJaSrAcdiX8aDg0j98Tua2T
jAdt3KY9Q3PBzTeb+E1mhjXjwpjgCQCI/rTWVZIgqjcHZTyFYtYIO0NwlG7qltnP
fBLxszidHQQCbXrJEv0GMfrhGZszhmDdBycdk6ApyNLFisTotOZ4sgC+Jph71wua
F3s+YiXhXXgLaw89GxD/8cHgn+Q9vZNDF0SwhH9svi98e1TBS7vl2gVsf3yw2S2e
rgyTE1a2huLeLryQQnLBq5QFxHgSX7VjH1rt0HD6q7GsuKoc30e3yWhgqlwtCF+Z
GLqpKLwsb5admnO1qdiwk1tob4BrJ+Tlx8sxdD6gF0NN98ycv12EjX0tClrtuRoa
6uWlLVgvj84lagNR5nJ8yFxquMMsHZ00zNq5u3hcA7MIrNT8bOADBW1vIMBNFM0r
6K9hItC7kd6euxi1iXmJT0L9MWOdpvwhOZnrUtQh692xO9dUPOn+WtU4RHMWKcpz
FWyJmn9SjGEpojHh4kGi
=eXDT
-----END PGP SIGNATURE-----




Reply sent to Balint Reczey <balint@balintreczey.hu>:
You have taken responsibility. (Fri, 03 Apr 2015 18:21:13 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Fri, 03 Apr 2015 18:21:13 GMT) (full text, mbox, link).


Message #17 received at 780372-close@bugs.debian.org (full text, mbox, reply):

From: Balint Reczey <balint@balintreczey.hu>
To: 780372-close@bugs.debian.org
Subject: Bug#780372: fixed in wireshark 1.8.2-5wheezy15
Date: Fri, 03 Apr 2015 18:17:26 +0000
Source: wireshark
Source-Version: 1.8.2-5wheezy15

We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 780372@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Balint Reczey <balint@balintreczey.hu> (supplier of updated wireshark package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 26 Mar 2015 21:03:38 +0100
Source: wireshark
Binary: wireshark-common wireshark tshark wireshark-dev wireshark-dbg wireshark-doc libwireshark2 libwsutil2 libwsutil-dev libwireshark-data libwireshark-dev libwiretap2 libwiretap-dev
Architecture: source all amd64
Version: 1.8.2-5wheezy15
Distribution: wheezy-security
Urgency: high
Maintainer: Balint Reczey <balint@balintreczey.hu>
Changed-By: Balint Reczey <balint@balintreczey.hu>
Description: 
 libwireshark-data - network packet dissection library -- data files
 libwireshark-dev - network packet dissection library -- development files
 libwireshark2 - network packet dissection library -- shared library
 libwiretap-dev - network packet capture library -- development files
 libwiretap2 - network packet capture library -- shared library
 libwsutil-dev - network packet dissection utilities library -- shared library
 libwsutil2 - network packet dissection utilities library -- shared library
 tshark     - network traffic analyzer - console version
 wireshark  - network traffic analyzer - GTK+ version
 wireshark-common - network traffic analyzer - common files
 wireshark-dbg - network traffic analyzer - debug symbols
 wireshark-dev - network traffic analyzer - development tools
 wireshark-doc - network traffic analyzer - documentation
Closes: 780372
Changes: 
 wireshark (1.8.2-5wheezy15) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.12.4 (Closes: #780372):
     - The WCP dissector could crash (CVE-2015-2188)
     - The pcapng file parser could crash (CVE-2015-2189)
     - The TNEF dissector could go into an infinite loop.
       Discovered by Vlad Tsyrklevich. (CVE-2015-2191)
Checksums-Sha1: 
 551fd7f7383a2d3e7ccf296ab8bd881f2f3954b7 2952 wireshark_1.8.2-5wheezy15.dsc
 26220d86cbd14108e175faf443ffa3017b3c00fb 138572 wireshark_1.8.2-5wheezy15.debian.tar.gz
 1a5b08243a16f42ff517d70015c4e180b7cfefae 3885204 wireshark-doc_1.8.2-5wheezy15_all.deb
 cd03ac3c247adfa7c8aea1bf722e7c66bb8670f0 1228844 libwireshark-data_1.8.2-5wheezy15_all.deb
 f041792312a5f3f734b1e03e46187a2f7be0e69f 229510 wireshark-common_1.8.2-5wheezy15_amd64.deb
 7790b2ebb3d94df83c40cb939dec3dc9b0511a2b 981338 wireshark_1.8.2-5wheezy15_amd64.deb
 04442bd6faf83c42cb5a8a67ce39866f6614fc07 178644 tshark_1.8.2-5wheezy15_amd64.deb
 d737b7ef08cd6b07ede873c871712772c71b0fdb 177998 wireshark-dev_1.8.2-5wheezy15_amd64.deb
 fbe6dc2390a731fb1e899112dbc48ae69a1c025e 28293562 wireshark-dbg_1.8.2-5wheezy15_amd64.deb
 3046cb3a702b1bae24c145ed88ccc2bd98bc5ef6 13442930 libwireshark2_1.8.2-5wheezy15_amd64.deb
 0350526c4ba8fcb38e46464d4e07118e5571dbf6 51218 libwsutil2_1.8.2-5wheezy15_amd64.deb
 4109d03cc9efddd1f886d648aff0d79bc9fb774f 50754 libwsutil-dev_1.8.2-5wheezy15_amd64.deb
 31e89f355f01e598df089ec8b49a50b5a645ad72 907212 libwireshark-dev_1.8.2-5wheezy15_amd64.deb
 30eeb4f17974e441b1e1cff921267b0b08476709 191654 libwiretap2_1.8.2-5wheezy15_amd64.deb
 464ed09ca04eb6d9c83c430cb1f63fcb9f10334c 71044 libwiretap-dev_1.8.2-5wheezy15_amd64.deb
Checksums-Sha256: 
 185ed2c0f6790e99a789ca2782e163a9ae28dfcdc36fb812768d5f873a33f2cf 2952 wireshark_1.8.2-5wheezy15.dsc
 9a6a9aabf4b1d53965516b4640f0a6b78e8e632b5f5532f9cb2ecf42885d2103 138572 wireshark_1.8.2-5wheezy15.debian.tar.gz
 65451f04cac906dd743b5f342ed4154acf7612f8422cb6d943948289c76a7309 3885204 wireshark-doc_1.8.2-5wheezy15_all.deb
 e3555a7d0abd91c54222fcea783fd5233306a41d2060d148af46c32e95ebf927 1228844 libwireshark-data_1.8.2-5wheezy15_all.deb
 e884e7baa2ec20a158b3e8cbd48de8023eeac90a6d6d0b6849983bab220143a7 229510 wireshark-common_1.8.2-5wheezy15_amd64.deb
 6ead757d64739778983eef246073605ae61832969f92bef039c8ea9b835cdb4f 981338 wireshark_1.8.2-5wheezy15_amd64.deb
 92f69ecdf603bbadd2b783978fd04ec629d1e8bc63133f9022e981d9117f9a62 178644 tshark_1.8.2-5wheezy15_amd64.deb
 6a7f2982578d03ede7c359854786510d16130b120103ce6eb4a7bab0d259771a 177998 wireshark-dev_1.8.2-5wheezy15_amd64.deb
 e1fc36f24a1dca2ff1a79ada861a92722e66fef8562aca465f9e2fa426d8c976 28293562 wireshark-dbg_1.8.2-5wheezy15_amd64.deb
 ac75070c0dfa69a7e528782c5f4448e57061407dbcb2dc1d083ddde074c60bb4 13442930 libwireshark2_1.8.2-5wheezy15_amd64.deb
 0a6a86a379194ab60c117c52fbd48aba8df2b4fb6f6239b85403da8c79fbf391 51218 libwsutil2_1.8.2-5wheezy15_amd64.deb
 21c0973a5adcf306c45512fda9f5e7dd72a5746fc896249df90c7bc4a4b94d0e 50754 libwsutil-dev_1.8.2-5wheezy15_amd64.deb
 3ed4eba6f03e88d1e9d36f1aac204e7c5755692fc72cfbe5716b02242e7515b3 907212 libwireshark-dev_1.8.2-5wheezy15_amd64.deb
 b87562679b1acc24e51234598b9cb43b422765c7c1b3560d8f367d03cbefb2f2 191654 libwiretap2_1.8.2-5wheezy15_amd64.deb
 64fb66683101ec41644518a006356104b38eafd34fc69701248b7d76a85d434a 71044 libwiretap-dev_1.8.2-5wheezy15_amd64.deb
Files: 
 28199dda87ef3ff1c8490ad07cf499e4 2952 net optional wireshark_1.8.2-5wheezy15.dsc
 be7d5f5e40f1c104837cdf064ec1cce9 138572 net optional wireshark_1.8.2-5wheezy15.debian.tar.gz
 d9b7f5f1cd74cdb2b6f18e36ad261ba4 3885204 doc extra wireshark-doc_1.8.2-5wheezy15_all.deb
 2b1fa425f2497859a5df8484223b4153 1228844 libs optional libwireshark-data_1.8.2-5wheezy15_all.deb
 94255c451c4447503a04b833f8b63875 229510 net optional wireshark-common_1.8.2-5wheezy15_amd64.deb
 a9ecc82d68ed98dbd5bbc97152c8e53b 981338 net optional wireshark_1.8.2-5wheezy15_amd64.deb
 ec6e5b8dee5b0e77b2ce49f5d0ef1418 178644 net optional tshark_1.8.2-5wheezy15_amd64.deb
 81012d8e60237e8aab0159b2cf16090a 177998 devel optional wireshark-dev_1.8.2-5wheezy15_amd64.deb
 5052650e5b3f08ba01584f53ff9c8f26 28293562 debug extra wireshark-dbg_1.8.2-5wheezy15_amd64.deb
 cf0cf95ef84cb97128ef88003e6f12a5 13442930 libs optional libwireshark2_1.8.2-5wheezy15_amd64.deb
 69b4bfc042cf5ce5cb711e50c2db9bdf 51218 libs optional libwsutil2_1.8.2-5wheezy15_amd64.deb
 994bcafc351f01e352ebb35bf9d231b4 50754 libdevel optional libwsutil-dev_1.8.2-5wheezy15_amd64.deb
 9af429b1aaad917c6341d6777e828662 907212 libdevel optional libwireshark-dev_1.8.2-5wheezy15_amd64.deb
 b22d99cf667a6aceb0b60bccadaa7910 191654 libs optional libwiretap2_1.8.2-5wheezy15_amd64.deb
 5cefb419c1534cda942f5004ab583ca8 71044 libdevel optional libwiretap-dev_1.8.2-5wheezy15_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVFIbdAAoJEPZk0la0aRp9La4QALXwX75r67YGP3/S86M7Yupk
9cMVSXbEK0ChCaRXre6rlaETLMP+jLGYWFYWU+vcxlZ0EOkOlWRFtmH34x5QdPBs
lBWCKgaEUhTKTivWxi9iAwym1vuGHgG9ZqgJ2ny1AetPDgFsNlUNGcDqnG8EsN4g
rPrfRnTU5MWk2NHhQqpr9cRsfmfOOk0oi96F7grr8CTo+OODK3KBccR+yBX2lB+P
RZp0oqXqQtvR2ld/OM4hvU/fZfQOUUM/89k3hGBAiwWbNOVrQm0oiYKZu0tmOmr2
F3DYNmAyWsahP9AEpRTLQteFbBEWqm0n4FoYHWNf5mXiTjeYZfI/7q9qgSP0T/kP
DK0AV9BQ52TMeBAuUK76sVZjF0nnrx+Jst/uQLuQBqWma2YYbsCZNtZzLEB4CeRL
ALg3E7oYd6c4xw1GCxFoCLlaqoUpSTXUj4Txq5lKLKZQDiA9l3j1pHKCRcvcWKZe
L8MjMIcZ11cnHrMjhMAqqj3vCq1X8pekUpK/mtvSKTnwa8nf/z+rigWH8xTVi5c8
Pza8mv0sI3ZeUv5drVUBbuSESkw6/8EFQ/6CvAOuxL+NSDbBdaRZtD4pMqtu6AL7
fTCHJrnLGX+bNgZPdQ8ipHZ4jx3JwhbuyDAFcjMAD5KWMaCWRHDNGJTxV5isCsC5
1iWGf9k2goYOKWHA6dxv
=ViPW
-----END PGP SIGNATURE-----




Reply sent to Balint Reczey <balint@balintreczey.hu>:
You have taken responsibility. (Tue, 14 Apr 2015 16:03:10 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <jmm@debian.org>:
Bug acknowledged by developer. (Tue, 14 Apr 2015 16:03:10 GMT) (full text, mbox, link).


Message #22 received at 780372-close@bugs.debian.org (full text, mbox, reply):

From: Balint Reczey <balint@balintreczey.hu>
To: 780372-close@bugs.debian.org
Subject: Bug#780372: fixed in wireshark 1.8.2-5wheezy15~deb6u1
Date: Tue, 14 Apr 2015 16:00:15 +0000
Source: wireshark
Source-Version: 1.8.2-5wheezy15~deb6u1

We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 780372@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Balint Reczey <balint@balintreczey.hu> (supplier of updated wireshark package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 12 Apr 2015 16:08:00 +0200
Source: wireshark
Binary: wireshark-common wireshark tshark wireshark-dev wireshark-dbg wireshark-doc libwireshark2 libwsutil2 libwsutil-dev libwireshark-data libwireshark-dev libwiretap2 libwiretap-dev
Architecture: source all amd64
Version: 1.8.2-5wheezy15~deb6u1
Distribution: squeeze-lts
Urgency: high
Maintainer: Balint Reczey <balint@balintreczey.hu>
Changed-By: Balint Reczey <balint@balintreczey.hu>
Description: 
 libwireshark-data - network packet dissection library -- data files
 libwireshark-dev - network packet dissection library -- development files
 libwireshark2 - network packet dissection library -- shared library
 libwiretap-dev - network packet capture library -- development files
 libwiretap2 - network packet capture library -- shared library
 libwsutil-dev - network packet dissection utilities library -- shared library
 libwsutil2 - network packet dissection utilities library -- shared library
 tshark     - network traffic analyzer - console version
 wireshark  - network traffic analyzer - GTK+ version
 wireshark-common - network traffic analyzer - common files
 wireshark-dbg - network traffic analyzer - debug symbols
 wireshark-dev - network traffic analyzer - development tools
 wireshark-doc - network traffic analyzer - documentation
Closes: 68746 179309 314833 419710 454621 539287 570132 582298 585370 591563 593214 593875 594390 594738 594780 596108 598498 608990 621801 626145 627146 630951 634671 635116 647082 649350 653938 661759 666058 678585 680056 689972 704561 709167 711918 769410 776135 780372
Changes: 
 wireshark (1.8.2-5wheezy15~deb6u1) squeeze-lts; urgency=high
 .
   * Rebuild for Squeeze LTS
 .
 wireshark (1.8.2-5wheezy15) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.12.4 (Closes: #780372):
     - The WCP dissector could crash (CVE-2015-2188)
     - The pcapng file parser could crash (CVE-2015-2189)
     - The TNEF dissector could go into an infinite loop.
       Discovered by Vlad Tsyrklevich. (CVE-2015-2191)
 .
 wireshark (1.8.2-5wheezy14) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.10.12 (Closes: #776135):
     - The DEC DNA Routing Protocol dissector could crash (CVE-2015-0562)
     - Wireshark could crash while decypting TLS/SSL sessions.
       Discovered by Noam Rathaus. (CVE-2015-0564)
 .
 wireshark (1.8.2-5wheezy13) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.10.11 (Closes: #769410):
     - SigComp UDVM buffer overflow (CVE-2014-8710)
     - AMQP crash (CVE-2014-8711)
     - NCP crashes (CVE-2014-8712, CVE-2014-8713)
     - TN5250 infinite loops (CVE-2014-8714)
 .
 wireshark (1.8.2-5wheezy12) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.10.9:
       - RTP dissector crash (CVE-2014-6422)
       - MEGACO dissector infinite loop (CVE-2014-6423)
       - Netflow dissector crash (CVE-2014-6424)
       - RTSP dissector crash (CVE-2014-6427)
       - SES dissector crash (CVE-2014-6428)
       - Sniffer file parser crash.
         (CVE-2014-6429, CVE-2014-6430, CVE-2014-6431, CVE-2014-6432)
 .
 wireshark (1.8.2-5wheezy11) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.10.9:
     - The Catapult DCT2000 and IrDA dissectors could underrun a buffer
       (CVE-2014-5161, CVE-2014-5162)
     - The GSM Management dissector could crash (CVE-2014-5163)
     - The RLC dissector could crash (CVE-2014-5164)
     - The ASN.1 BER dissector could crash (CVE-2014-5165)
 .
 wireshark (1.8.2-5wheezy10) wheezy-security; urgency=low
 .
   * security fixes from Wireshark 1.8.13:
      - The NFS dissector could crash. Discovered by Moshe Kaplan
        (CVE-2014-2281)
      - The RLC dissector could crash. (CVE-2014-2283)
      - The MPEG file parser could overflow a buffer.
        Discovered by Wesley Neelen. (CVE-2014-2299)
 .
 wireshark (1.8.2-5wheezy9) wheezy-security; urgency=high
 .
   * security fixes from (not yet released) Wireshark 1.8.13:
     -  The BSSGP dissector could crash. Discovered by Laurent Butti.
        (CVE-2013-7113)
        The exploit provided for CVE-2013-7113 does not crash 1.8.2-5wheezy8
        and earlier versions, but a modified exploit could. The fix is
        back-ported from Wireshark's 1.8.x branch.
 .
 wireshark (1.8.2-5wheezy8) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.12:
     - The NTLMSSP v2 dissector could crash. Discovered by Garming Sam.
       (CVE-2013-7114)
 .
 wireshark (1.8.2-5wheezy7) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.11:
     - The IEEE 802.15.4 dissector could crash. (CVE-2013-6336)
     - The NBAP dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-6337)
     - The SIP dissector could crash.
       (CVE-2013-6338)
     - The TCP dissector could crash. (CVE-2013-6340)
 .
 wireshark (1.8.2-5wheezy6) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.10:
     - NBAP dissector could crash. Discovered by Laurent Butti.
       (No assigned CVE number)
     - The RTPS dissector could overflow a buffer. Discovered by
       Ben Schmidt. (No assigned CVE number)
     - The LDAP dissector could crash. (No assigned CVE number)
     - The Netmon file parser could crash. Discovered by G. Geshev.
 .
 wireshark (1.8.2-5wheezy5) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.9:
     - The DVB-CI dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-4930)
     - The GSM A Common dissector could crash. (CVE-2013-4932)
     - The Netmon file parser could crash. Discovered by G. Geshev.
       (CVE-2013-4933, CVE-2013-4934)
     - The ASN.1 PER dissector could crash. Discovered by Oliver-Tobias Ripka.
       (CVE-2013-4935)
 .
 wireshark (1.8.2-5wheezy4) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.8 (Closes: #711918):
       - The CAPWAP dissector could crash. Discovered by Laurent Butti.
         (CVE-2013-4074)
       - The GMR-1 BCCH dissector could crash.
         Discovered by Sylvain Munaut and Laurent Butti. (CVE-2013-4075)
       - The PPP dissector could crash. Discovered by Laurent Butti.
         (CVE-2013-4076)
       - The NBAP dissector could crash. (CVE-2013-4077)
       - The RDP dissector could crash. Discovered by Laurent Butti.
         (CVE-2013-4078)
       - The HTTP dissector could overrun the stack. (CVE-2013-4081)
       - The Ixia IxVeriWave file parser could overflow the heap.
         Discovered by Sachin Shinde. (CVE-2013-4082)
       - The DCP ETSI dissector could crash. (CVE-2013-4083)
 .
 wireshark (1.8.2-5wheezy3) wheezy-security; urgency=high
 .
   * security fixes from Wireshark 1.8.7 (Closes: #709167):
     - The GTPv2 dissector could crash (CVE-2013-3555)
     - The ASN.1 BER dissector could crash (CVE-2013-3557)
     - The PPP CCP dissector could crash (CVE-2013-3558)
     - The DCP ETSI dissector could crash. Discovered by Evan Jensen.
       (CVE-2013-3559)
     - The MPEG DSM-CC dissector could crash. (CVE-2013-3560)
     - The Websocket dissector could crash. Discovered by Moshe Kaplan.
       (CVE-2013-3562)
 .
 wireshark (1.8.2-5wheezy2) wheezy-proposed-updates; urgency=low
 .
   * make libwsutil-dev confict with and replace wireshark-dev (<< 1.4.0~rc2-1)
     (Closes: #704561)
 .
 wireshark (1.8.2-5wheezy1) wheezy-security; urgency=high
 .
   * re-upload to Wheezy security without changes in the content
 .
 wireshark (1.8.2-5) unstable; urgency=high
 .
   * security fixes from Wireshark 1.8.6:
     - The TCP dissector could crash (CVE-2013-2475)
     - The CSN.1 dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-2477)
     - MMS dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-2478)
     - The RTPS and RTPS2 dissectors could crash. Discovered by Alyssa Milburn.
       (CVE-2013-2480)
     - The Mount dissector could crash. Discovered by Alyssa Milburn.
       (CVE-2013-2481)
     - The ACN dissector could attempt to divide by zero.
       Discovered by Alyssa Milburn. (CVE-2013-2483)
     - The CIMD dissector could crash. Discovered by Moshe Kaplan.
       (CVE-2013-2484)
     - The DTLS dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-2488)
 .
 wireshark (1.8.2-4) unstable; urgency=high
 .
   * security fixes from Wireshark 1.8.5:
     - The CLNP dissector could crash. Discovered independently by
       Laurent Butti and the Wireshark development team (CVE-2013-1582)
     - The DTN dissector could crash (CVE-2013-1583, CVE-2013-1584)
     - The MS-MMC dissector (and possibly others) could crash (CVE-2013-1585)
     - The DTLS dissector could crash. Discovered by Laurent Butti.
       (CVE-2013-1586)
     - The ROHC dissector could crash (CVE-2013-1587)
     - The DCP-ETSI dissector could corrupt memory. Discovered by Laurent Butti.
       (CVE-2013-1588)
     - The Wireshark dissection engine could crash. Discovered by Laurent Butti.
     - The NTLMSSP dissector could overflow a buffer. Discovered by
       Ulf Härnhammar. (CVE-2013-1590)
 .
 wireshark (1.8.2-2) unstable; urgency=high
 .
   * security fixes from Wireshark 1.8.3 (Closes: #689972):
     - The HSRP dissector could go into an infinite loop (CVE-2012-5237)
     - The PPP dissector could abort (CVE-2012-5238)
     - Martin Wilck discovered an infinite loop in the DRDA dissector
       (CVE-2012-5239)
     - Laurent Butti discovered a buffer overflow in the LDP dissector
       (CVE-2012-5240)
 .
 wireshark (1.8.2-1) unstable; urgency=high
 .
   * New upstream release 1.8.2 (skipping 1.8.1 in Debian)
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.8.2.html
     - security fixes:
       - The PPP dissector could crash (Closes: #680056)(CVE-2012-4048)
       - The NFS dissector could use excessive amounts of CPU (CVE-2012-4049)
       - The DCP ETSI dissector could trigger a zero division. Reported by
          Laurent Butti. (CVE-2012-4285)
       - The MongoDB dissector could go into a large loop. Reported by
 	 Ben Schmidt. (CVE-2012-4287)
       - The XTP dissector could go into an infinite loop. Reported by
 	 Ben Schmidt. (CVE-2012-4288)
       - The ERF dissector could overflow a buffer. Reported by
 	 Laurent Butti. (CVE-2012-4294 CVE-2012-4295)
       - The AFP dissector could go into a large loop. Reported by
 	 Stefan Cornelius. (CVE-2012-4289)
       - The RTPS2 dissector could overflow a buffer. Reported by
 	 Laurent Butti. (CVE-2012-4296)
       - The GSM RLC MAC dissector could overflow a buffer. Reported by
 	 Laurent Butti. (CVE-2012-4297)
       - The CIP dissector could exhaust system memory. Reported by
 	 Ben Schmidt. (CVE-2012-4291)
       - The STUN dissector could crash. Reported by Laurent Butti.
 	 (CVE-2012-4292)
       - The EtherCAT Mailbox dissector could abort. Reported by
 	 Laurent Butti. (CVE-2012-4293)
       - The CTDB dissector could go into a large loop. Reported by
 	 Ben Schmidt. (CVE-2012-4290)
       - The pcap-ng file parser could trigger a zero division (CVE-2012-4286)
       - The Ixia IxVeriWave file parser could overflow a buffer
 	 (CVE-2012-4298)
 .
 wireshark (1.8.0-1) unstable; urgency=low
 .
   * New upstream release 1.8.0 (Closes: #678585)
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.8.0.html
   * fix lintian pedantic mode warnings
     - use set -e in maintainer scripts
     - refer to GPLv2 via symlink
     - fix spacing in debian/control
     - depend on debhelper (>= 9)
 .
 wireshark (1.8.0~rc1-1) unstable; urgency=low
 .
   * New upstream release 1.8.0 release candidate 1
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.8.0.html
     - drop 07_use-theme-icon.patch as it has been integrated upstream
     - bump library versions to 2.0.0 and rename library packages to
       libwsutil2, libwiretap2 and libwireshark2
 .
 wireshark (1.6.8-1) unstable; urgency=medium
 .
   * New upstream release 1.6.8
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.8.html
     - security fixes:
       - Infinite and large loops in the ANSI MAP, ASF, BACapp, Bluetooth
         HCI, IEEE 802.11, IEEE 802.3, LTP, and R3 dissectors have been
         fixed (No assigned CVE number)
       - The DIAMETER dissector could try to allocate memory improperly
         and crash (No assigned CVE number)
       - Wireshark could crash on SPARC processors due to misaligned
         memory. Discovered by Klaus Heckelmann (No assigned CVE number)
     - NEWS file is empty, stop shipping it in Debian package
   * update standards-version to 3.9.3
   * use dpkg-buildflags for hardening
   * depend on dpkg-dev (>= 1.16.1~) for dpkg-buildflags
   * bump debhelper compatibility level to v9
 .
 wireshark (1.6.7-1) unstable; urgency=low
 .
   * New upstream release 1.6.7
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.7.html
 .
 wireshark (1.6.6-1) unstable; urgency=high
 .
   * New upstream release 1.6.6
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.6.html
     - security fixes (Closes: #666058):
       - The ANSI A dissector could dereference a NULL pointer and crash
       - The IEEE 802.11 dissector could go into an infinite loop
       - The pcap and pcap-ng file parsers could crash trying to read ERF data
       - The MP2T dissector could try to allocate too much memory and crash
   * depend on automake instead of automake1.9
   * update watch file to watch bzip2 compressed archives
 .
 wireshark (1.6.5-2) unstable; urgency=low
 .
   * clarify when set-user-id bit is set for dumpcap in README.Debian
     (Closes: #649350)
   * add notes about capturing USB frames to README.Debian
   * package and use SVG icon for Wireshark (Closes: #661759)
 .
 wireshark (1.6.5-1) unstable; urgency=high
 .
   * New upstream release 1.6.5
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.5.html
     - security fixes:
       - Laurent Butti discovered that Wireshark failed to properly check
         record sizes for many packet capture file formats.
         (No assigned CVE number.)
       - Wireshark could dereference a NULL pointer and crash.
         (No assigned CVE number.)
       - The RLC dissector could overflow a buffer.
         (No assigned CVE number.)
   * build architecture dependent and independent packages separately
   * [Debconf translation updates]
     - Indonesian (Mahyuddin Susanto). (Closes: #653938)
 .
 wireshark (1.6.4-1) unstable; urgency=low
 .
   * New upstream release 1.6.4
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.4.html
   * remove Joost Yervante Damad from uploaders as he has resigned
     Thank you Joost for taking care of Wireshark packages for many years!
 .
 wireshark (1.6.3-1) unstable; urgency=high
 .
   * New upstream release 1.6.3
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.3.html
     - security fixes:
       - The CSN.1 dissector could crash
         (No assigned CVE number.)
       - Huzaifa Sidhpurwala of Red Hat Security Response Team discovered
         that the Infiniband dissector could dereference a NULL pointer.
         (No assigned CVE number.)
       - Huzaifa Sidhpurwala of Red Hat Security Response Team discovered a
         buffer overflow in the ERF file reader. (No assigned CVE number.)
     -  bump library versions
   * add build-arch and build-indep targets to debian/rules
   * [Debconf translation updates]
     - Slovak (Slavko). (Closes: #647082)
 .
 wireshark (1.6.2-1) unstable; urgency=high
 .
   * New upstream release 1.6.2
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.2.html
     - security fixes
       - A large loop in the OpenSafety dissector could cause a crash.
         (CVE-2011-3484)
       - A malformed IKE packet could consume excessive resources.
         (CVE-2011-3266)
       - A malformed capture file could result in an invalid root tvbuff and
         cause a crash. (CVE-2011-3483 )
       - Wireshark could run arbitrary Lua scripts. (CVE-2011-3360)
       - The CSN.1 dissector could crash. (CVE-2011-3482)
     - don't show subversion revision in window title (Closes: #635116)
 .
 wireshark (1.6.1-1) unstable; urgency=high
 .
   * New upstream release 1.6.1
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.1.html
     - security fixes
        - The Lucent/Ascend file parser was susceptible to an infinite loop
          (CVE-2011-2597)
        - The ANSI MAP dissector was susceptible to an infinite loop
          (No assigned CVE number.)
   * use linux-any wildcard for architecture-specific dependencies
     (Closes: #634671)
 .
 wireshark (1.6.0-2) unstable; urgency=low
 .
   * [Debconf translation updates]
     - Korean (si-cheol KO). (Closes: #630951)
   * show a hint to read README.Debian when showing the warning about
     running Wireshark as root
     Thanks to Evan Huus for the suggestion.
   * don't ship .la files for plugins, it keeps lintian happy
   * migrate to dh_python2 from dh_pysupport
   * use dh_prep instead of obsoleted dh_clean -k in debian/rules
 .
 wireshark (1.6.0-1) unstable; urgency=low
 .
   * New upstream release 1.6.0
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.6.0.html
     - Decode protocols selectively using tshark -O (Closes: #179309)
     - Support opening files larger than 2GB on all platforms
       (Closes: #539287)
     - Bump library versions (Closes: #627146)
   * depend on omniidl instead of omniidl4 transitional package
   * [Debconf translation updates]
     - Dutch (Jeroen Schot). (Closes: #626145)
     - Hungarian (Balint Reczey).
   * start shipping libwireshark2, libwiretap2 and libwsutil2 instead of
     libwireshark0, libwiretap0 and libwsutil0, respectively
   * drop 05_bump_so_versions.patch as upstream started library versioning
 .
 wireshark (1.5.1-1) experimental; urgency=low
 .
   * New upstream development release 1.5.1
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.5.1.html
   * update standards-version to 3.9.2
   * clarify in README.Debian that only root is able to capture packets in
     default installation (Closes: #621801)
 .
 wireshark (1.5.0-1) experimental; urgency=low
 .
   * New upstream development release 1.5.0
     - release notes:
       http://www.wireshark.org/news/20110124.html
     - Allow <interval> to be successfully sscanf'd no matter the locale
       for the decimal symbol (Closes: #454621)
     - Use more meaningful temp file name (Closes: #419710)
 .
 wireshark (1.4.3-2) unstable; urgency=low
 .
   * re-upload to unstable
 .
 wireshark (1.4.3-1) experimental; urgency=high
 .
   * New upstream release 1.4.3
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.4.3.html
     - security fixes
        - FRAsse discovered that the MAC-LTE dissector could overflow a buffer.
          (No assigned CVE number.)
        - FRAsse discovered that the ENTTEC dissector could overflow a buffer.
          (CVE-2010-4538) (Closes: #608990)
        - The ASN.1 BER dissector could assert and make Wireshark exit
          prematurely. (No assigned CVE number.)
   * drop 25_libwsutil-version.patch since it has been integrated upstream
 .
 wireshark (1.4.2-3) experimental; urgency=low
 .
   [ W. Borgert ]
   * support IDL's #include in idl2deb (Closes: #314833)
 .
   [ Balint Reczey ]
   * really ship include files in libwsutil-dev
   * raise Python 2.6 compatible exceptions (Closes: #585370)
 .
 wireshark (1.4.2-2) experimental; urgency=low
 .
   * separated libwsutil and related headers in libwsutil0 and
     libwsutil-dev packages
 .
 wireshark (1.4.2-1) experimental; urgency=low
 .
   * New upstream release 1.4.2
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.4.2.html
     - security fixes
        - Nephi Johnson of BreakingPoint discovered that the LDSS dissector
          could overflow a buffer. (No assigned CVE number.)
        - The ZigBee ZCL dissector could go into an infinite loop.
          (No assigned CVE number.)
   * drop 05_fix-display-filter-update-when-changing-profile.patch
     patch since it has been integrated upstream
 .
 wireshark (1.4.1-1) experimental; urgency=high
 .
   * New upstream release 1.4.1
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.4.1.html
     - add support for sll.ltype hooks (Closes: #594390)
     - security fixes
        - The Penetration Test Team of NCNIPC (China) discovered that the
          ASN.1 BER dissector was susceptible to a stack overflow
          (CVE-2010-3445)
   * pick fix for improperly backported display filter update when changing
     profile
   * [Debconf translation updates]
     - Basque (Iñaki Larrañaga Murgoitio).
     - Vietnamese (Clytie Siddall). (Closes: #598498)
   * make wireshark-dev depend on libwireshark-dev and libwiretap-dev
     (Closes: #596108)
 .
 wireshark (1.4.0-1) experimental; urgency=low
 .
   [ Balint Reczey ]
   * New upstream release 1.4.0
     - release notes:
       http://www.wireshark.org/docs/relnotes/wireshark-1.4.0.html
   * drop 26_offline-documentation.patch patch since it has been integrated
     upstream
   * [Debconf translation updates]
     - French (Simon Paillard). (Closes: #593214)
     - Danish (Joe Hansen). (Closes: #594738)
     - Brazilian Portuguese (Adriano Rafael Gomes). (Closes: #594780)
     - Basque (Iñaki Larrañaga Murgoitio).
   * changed versioned conflicts to conflict with << 1.4.0~rc2-1 versions
     instead of conflicting with <= 1.2.7-1 ones to allow smooth upgrades
     from versions between 1.2.7-1 and 1.4.0~rc2-1 (Closes: #593875)
   * debian/control: updated policy to 3.9.1 (Eloy Paris removed the .la
     files to become compliant)
 .
   [ Eloy Paris ]
   * Removed /usr/lib/libwiretap.la from the libwiretap-dev package and
     /usr/lib/libwireshark.la and /usr/lib/libwsutil.la from the
     libwireshark-dev package since external programs linking against
     libwiretap and libwireshark do not need them. Refer to the Debian
     Policy Manual 10.2 ("Libraries") for further information.
 .
 wireshark (1.4.0~rc2-2) experimental; urgency=low
 .
   * New wireshark-doc package for shipping offline documentation
     (Closes: #68746)
   * make libwireshark0-data suggest snmp-mibs-downloader instead of
     wireshark-common
   * [Debconf translation updates]
     - Japanese (Hideki Yamane (Debian-JP)).  (Closes: #591563)
 .
 wireshark (1.4.0~rc2-1) experimental; urgency=low
 .
   [ Eloy Paris ]
   * New upstream release.
     - Make tshark list interfaces for non-root user (Closes: #582298)
     - Fix duplicate inconsistent attributes in RADIUS dictionary.
       (Closes: #570132)
   * New libwireshark0, libwireshark-dev, libwiretap0, libwiretap-dev
     packages that reorganize libraries, header files, etc. as follows:
     - Moved libwireshark.so.* from package wireshark-common to package
       libwireshark0.
     - Moved libwsutil.so.* from package wireshark-common to package
       libwireshark0.
     - Moved libwiretap.so.* from package wireshark-common to package
       libwiretap0.
     - Moved header files, .so symlinks, and static libraries from package
       wireshark-dev to libwireshark-dev and libwiretap-dev, depending on
       the case.
     - Moved plugins in /usr/lib/wireshark/ from package wireshark-common
       to package libwireshark0.
     This provides more package granularity and allows easier use of
     libraries provided by the Wireshark project by applications that
     are not maintained by the Wireshark project (package kismet currently
     appears to use services offered by libwiretap, and upcoming package
     netexpect will use libwireshark services [see ITP bug #587056]).
   * Dropped 23_lintian-overrides.patch since we no longer have binaries
     with RPATHs because after the library separation work mentioned above
     our libraries are in /usr/lib and not in /usr/lib/wireshark, eliminating
     the need for RPATHs. Also tweaked debian/rules, debian/tshark.files,
     and debian/wireshark-common.files so the lintian overrides
     are not installed.
   * Dropped the following patches since they have been integrated
     upstream:
     - 05_libsnmp_path.patch
     - 07_mib_tip.patch
     - 11_disable_oid_resolution_by_default.patch
     - 12_fix_about_crash.patch
     - 21_dumpcap.patch
 .
   [ Balint Reczey ]
   * Dropped the following patches since they have been integrated
     upstream:
     - 10_prevent_libsmi_crash.patch
     - 04_asn2wrs_ply.patch
     - 06_giop-buffer.patch
   * moved platform independent files needed by libwireshark0 to
     new libwireshark0-data package from wireshark-common
   * New upstream release 1.4.0~rc2
Checksums-Sha1: 
 f13942518ff6ba55f99b5d55e726b3b237b00f90 2529 wireshark_1.8.2-5wheezy15~deb6u1.dsc
 8450af00dc89e84cdd549dafe0aa24ef72eba748 141988 wireshark_1.8.2-5wheezy15~deb6u1.debian.tar.gz
 c98f6c4695fabf9977b4475adc7418c81350fcf7 3885316 wireshark-doc_1.8.2-5wheezy15~deb6u1_all.deb
 e157fb22540fca64c6557d682181339671ab931d 1228876 libwireshark-data_1.8.2-5wheezy15~deb6u1_all.deb
 85becec9dc2708f5895f9fd52938880e7c3a3b58 229344 wireshark-common_1.8.2-5wheezy15~deb6u1_amd64.deb
 fb723cc9cbf3ff4d62eba31eb391b72e83135b69 976648 wireshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 30f8055f784c28708ee76559b26345d545a92ca1 177498 tshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 8b762ab5ec915dbca1259eded39bcb93e9a8a0c6 177662 wireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 863fe8794694868265046ade5331efd1291a7783 19907536 wireshark-dbg_1.8.2-5wheezy15~deb6u1_amd64.deb
 664fa861319ddacfa8fc486529e02738a725cc6b 13408880 libwireshark2_1.8.2-5wheezy15~deb6u1_amd64.deb
 33ada52cd06de398fb88c4e997f853373c66eca6 51150 libwsutil2_1.8.2-5wheezy15~deb6u1_amd64.deb
 101a9f653e1c4cf5bd45904ef1e8c323fa12e245 50790 libwsutil-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 debbc391c0b6acf44f4769f5d0388252c9b0e475 907184 libwireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 2573bba841fd465a5d5414084850108e8d278e38 192684 libwiretap2_1.8.2-5wheezy15~deb6u1_amd64.deb
 a54836ec972b4a358156b70ae5d64ce1d2a2fbdd 71090 libwiretap-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
Checksums-Sha256: 
 889d6a327b9561de98d6eb8630466f5d5cede28acfd6cba18ce234dea823bc57 2529 wireshark_1.8.2-5wheezy15~deb6u1.dsc
 6ba7843b4f9cc1001e5c89b30d0a9ff12b6e0e5d4e492b8660eaa644d31e2a66 141988 wireshark_1.8.2-5wheezy15~deb6u1.debian.tar.gz
 895b1a66babf4caa9b5d7f5b9c2d132472e4c6837c39f8424ad5d1503aa304ba 3885316 wireshark-doc_1.8.2-5wheezy15~deb6u1_all.deb
 b2f261b3502bcc310f8ae5fdfa0b29b558895502b12fa8868c087ca90ad9913e 1228876 libwireshark-data_1.8.2-5wheezy15~deb6u1_all.deb
 f38b407226e78742b9c1eca336d802e019add4e4e0a45e5cca0f83a7ca6eecf7 229344 wireshark-common_1.8.2-5wheezy15~deb6u1_amd64.deb
 e1573b3aa3e8a9ad21fe11401e2dd769bf57f51100a749712e4f70249fdf79ca 976648 wireshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 976aae4b94b1653356006214e8c182f089ad1144fe59dfecd6e27ab7acdc84fe 177498 tshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 3512e3669a707dfe070dc887d38eb87bcb75f3eb736fdc9101df5128f33b3337 177662 wireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 b922daee3c659e31dd5656cc6b7ad67c68d97eccfe63fd0753edda1f9a0c9e46 19907536 wireshark-dbg_1.8.2-5wheezy15~deb6u1_amd64.deb
 48f93298c870aead869b3ef8a47ea8251a08e8383636e30bca20fc7a67b60cf7 13408880 libwireshark2_1.8.2-5wheezy15~deb6u1_amd64.deb
 c236800d3aaf75ac4381f5e251b173933b397bd1b73fb3e84b49e443c934c916 51150 libwsutil2_1.8.2-5wheezy15~deb6u1_amd64.deb
 8ab7e0d52d138c6520b6798d3134b96bf6cd3052b21e4f90f6199019b68160ed 50790 libwsutil-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 c6eac65315b23070b9a4bfdff21f3188117e48361e5f825f5a5601f9ed04121b 907184 libwireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 514b00ab6627661a23aeb8ea4f26ed5274f2020059d45e4d6613f5c82e94c69b 192684 libwiretap2_1.8.2-5wheezy15~deb6u1_amd64.deb
 b3f3d9632cadcfc661ce0cf4a90eb335673eaef135fa247e77410f8fd90736a2 71090 libwiretap-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
Files: 
 d496363591fdc2e9f1fe3c9eff866742 2529 net optional wireshark_1.8.2-5wheezy15~deb6u1.dsc
 7d0e9f0ef9ad67766240ff58cb71c337 141988 net optional wireshark_1.8.2-5wheezy15~deb6u1.debian.tar.gz
 254cda3018e7d0387c27f7786d9a1b09 3885316 doc extra wireshark-doc_1.8.2-5wheezy15~deb6u1_all.deb
 05a4ba8d5c313d142df9b2f72809a37e 1228876 libs optional libwireshark-data_1.8.2-5wheezy15~deb6u1_all.deb
 1fe1c62885d983786885b32007fc2def 229344 net optional wireshark-common_1.8.2-5wheezy15~deb6u1_amd64.deb
 61091b06eb92d4d5a00a8eeeea431d91 976648 net optional wireshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 cf49a7cf2781e82fc920eec8d768d4a6 177498 net optional tshark_1.8.2-5wheezy15~deb6u1_amd64.deb
 ca8019f03568b54aacd7b8792e21492b 177662 devel optional wireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 66401c2665bd2b09cfe8b04a47a99008 19907536 debug extra wireshark-dbg_1.8.2-5wheezy15~deb6u1_amd64.deb
 747592c16ebe90d6eb90531b0e73426a 13408880 libs optional libwireshark2_1.8.2-5wheezy15~deb6u1_amd64.deb
 63417b6da2e665699a9a9f49c9b44bb4 51150 libs optional libwsutil2_1.8.2-5wheezy15~deb6u1_amd64.deb
 1b4a73b408bf49c0a9ed29d0ca1a62d8 50790 libdevel optional libwsutil-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 640aecb430eddd7c8f360c9f712ef78d 907184 libdevel optional libwireshark-dev_1.8.2-5wheezy15~deb6u1_amd64.deb
 2a2f672be399b719a08b2c2011a2c9cb 192684 libs optional libwiretap2_1.8.2-5wheezy15~deb6u1_amd64.deb
 a7533855dd9fd55bd07280b308f4a5d5 71090 libdevel optional libwiretap-dev_1.8.2-5wheezy15~deb6u1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVKqCsAAoJEPZk0la0aRp9FbkP/jxVdO62pA2MNWMBYDsBinZP
4hKShCZSfcvwEwEeyznl+BLMtKm3m+jHmqO5hFzUmOK/cElbtrN1jyeLBGcgG/kz
E4Ua7kUIjTgbc8kc6zsS2JScMsqYvBAZZnxUUSeXhY7s6ESFy4fJgJ1n+e2zfUEr
Qu38dNFm7uQ4Bc9wukmgM32so7XiQgr2o07L4e0tDirbwpnT6DSaZN3G+QH1E+y+
D8D5dKZwMsJsLSLnix722FREdnwNyxaCOTILUhMq9jdxUVfLqd7KQ2xJexS8OpkX
BxCthYSbHP9mwh4lCM7VdQYsTAlIoyCmXZmg0vp11JQxoSVqHpRtEqzK1X8KRnl4
ACWiVOaalMvVNQf4jYU2xJHrDdQjyLvln0dnz1HbVC8mmZ0zCwVNPDvCXAMWYGSO
qYrsAQ2FXaa9HvWtBum2+UyP74S7YcYffCBuhrsQYXSF0gS4kmccaRGovxLrgFh6
Mhk6Kpo0T+qvaRLo2taKL1TTp1ifgieqiKBCFZOYLVrI4JYLak7vgMVuUf2yskuJ
3JnIhmBaKRQZwM9YBmOlJA8VEUEgbpcgueAZ/uZ3tHwGbxIshq1N0YZOP03CT9Is
8Ha6pvSe4xUDop9MI0PIEPHsfK1ix8afm3zmTVc26DXzCOowqh4bblyYxasFjyR8
w9PyLLko71snU9vTBBLE
=1uct
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Wed, 13 May 2015 07:29:38 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:44:32 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.