Your message dated Sun, 27 Oct 2024 14:32:09 +0000
with message-id <[email protected]>
and subject line Bug#1068111: fixed in wireshark 4.0.17-0+deb12u1
has caused the Debian Bug report #1068111,
regarding wireshark: CVE-2024-2955
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1068111: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068111
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: wireshark
Version: 4.2.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.com/wireshark/wireshark/-/issues/19695
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for wireshark.
CVE-2024-2955[0]:
| T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13
| allows denial of service via packet injection or crafted capture
| file
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-2955
https://www.cve.org/CVERecord?id=CVE-2024-2955
[1] https://www.wireshark.org/security/wnpa-sec-2024-06.html
[2] https://gitlab.com/wireshark/wireshark/-/issues/19695
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: wireshark
Source-Version: 4.0.17-0+deb12u1
Done: Adrian Bunk <[email protected]>
We believe that the bug you reported is fixed in the latest version of
wireshark, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Adrian Bunk <[email protected]> (supplier of updated wireshark package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 30 Sep 2024 10:55:30 +0300
Source: wireshark
Architecture: source
Version: 4.0.17-0+deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Balint Reczey <[email protected]>
Changed-By: Adrian Bunk <[email protected]>
Closes: 1059925 1068111 1080298
Changes:
wireshark (4.0.17-0+deb12u1) bookworm; urgency=medium
.
* Non-maintainer upload.
* New upstream release.
- CVE-2024-0208: GVCP dissector crash
- CVE-2024-0209: IEEE 1609.2 dissector crash
- CVE-2024-2955: T.38 dissector crash (Closes: #1068111)
- CVE-2024-4853: Editcap byte chopping crash
- CVE-2024-4854: MONGO dissector infinite loop
- CVE-2024-4855: Editcap use-after-free
- CVE-2024-8250: NTLMSSP dissector crash (Closes: #1080298)
- CVE-2024-8645: SPRT dissector crash
* CVE-2024-0211: DOCSIS dissector crash
* Closes: #1059925
Checksums-Sha1:
a174e14ff40ab513b7dc045f6a40355db3f49132 3384 wireshark_4.0.17-0+deb12u1.dsc
593b93ee5e32c5e84ef0f1318081b9055342a2b5 46774565 wireshark_4.0.17.orig.tar.bz2
5cf6d31e23f035eeffa225594754935b24fb1776 80432
wireshark_4.0.17-0+deb12u1.debian.tar.xz
Checksums-Sha256:
1e52ba5b453e3e900f7817f7fbfbc901289d7a8e575534ef3eb175812c7d54bf 3384
wireshark_4.0.17-0+deb12u1.dsc
62fd1491b6211d1651a16a45ead15808970b3a6a9ebde2537f96722af47aaaa5 46774565
wireshark_4.0.17.orig.tar.bz2
1cab8b6868075d749aed34761076926d67ec88c36db505a8f2d1223d43b8822f 80432
wireshark_4.0.17-0+deb12u1.debian.tar.xz
Files:
46b23600cefbbdb340d924e0fccfbbf5 3384 net optional
wireshark_4.0.17-0+deb12u1.dsc
067d2c6fbf7a2b660b798e6a12079319 46774565 net optional
wireshark_4.0.17.orig.tar.bz2
fb4b2f62f5cee5f694aedcf33f1bfa2b 80432 net optional
wireshark_4.0.17-0+deb12u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmcTudwACgkQiNJCh6LY
mLHAyBAAh1/zCvGaxm0I6Wjs/+9oS5bCUnscpelY5GzkEZTuBNI8375YZD4e5tly
wjn1o/9NEAx8ccbezjSTspvUQ0GqAeCN0ZaVQ/c69XOwqUrBI2FrYZiQuLZlZMwF
ULiRx44xwMTXOWQlq60k3Zxyda57Zavi01d+/R7YFRjZXpn2+Syk1mDFVOC8IUO3
PbNoX/yefJFcfo7fxC35a7MboarL60JmWFEppJQLawZsnkyynDxzPzr/vkT07B/g
mbtuF4YllEozm8vIM/4mdlOpXRZpw5LpLd4F2y9kTgs5n8IVvW1JJRsrZaDc8gKn
MycIyIjpBclkom2tr8L5LH8B4GD0pFMGzA+u/zuKrJcd54fhmnd2J1fvSjqaaoBm
DF4pQ2atzUowVEmagQEOokzDko2der1DXek3ZgTEEqZg357T+GFN6bZayMHmyueN
naeZLzbkI/SgAJrHyjskDXZoWi+nnLG1xJEuZU4KtPgUK3xqj+gzpKFSBu4I/XUQ
dU2V67beS3OHvTSVtT9p01PH+jfwDdP2HRRAc1orubT+IyjB6eCGC3SOb6TB3KOq
0KfkS9TVpPzZ7yr/EFbmX+W4YRgScBnej3GW7Muslr0eUiGfaQncKhH8uH2kddb/
zIkro5cLTkviSfSuP3vCMr71cucDV/QNxMccI4vNwNq+C4Zf1Ss=
=TV+0
-----END PGP SIGNATURE-----
pgpi__uv1NaB2.pgp
Description: PGP signature
--- End Message ---