From 53dffd7a244fd7bab0f1b239069bc5efd17a588c Mon Sep 17 00:00:00 2001 From: Chris Lamb Date: Mon, 3 Jan 2022 16:27:36 +0000 Subject: Triage CVE-2021-4181, CVE-2021-4182, CVE-2021-4183, CVE-2021-4184, CVE-2021-4186 & CVE-2021-4190 in wireshark for stretch LTS. --- data/CVE/2021.list | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index cf9aee7a52..0d4bda95c1 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -238,6 +238,7 @@ CVE-2021-4190 (Large loop in the Kafka dissector in Wireshark 3.6.0 allows denia - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-22.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17811 CVE-2021-4189 [ftplib should not use the host from the PASV response] @@ -343,36 +344,42 @@ CVE-2021-4186 (Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allow - wireshark 3.6.0-1 [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-16.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17737 CVE-2021-4185 (Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3 ...) - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-17.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17745 CVE-2021-4184 (Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3 ...) - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-18.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17754 CVE-2021-4183 (Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of se ...) - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-19.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17755 CVE-2021-4182 (Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 ...) - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-20.html NOTE: https://gitlab.com/wireshark/wireshark/-/issues/17801 CVE-2021-4181 (Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3. ...) - wireshark [bullseye] - wireshark (Minor issue) [buster] - wireshark (Minor issue) + [stretch] - wireshark (Minor issue) NOTE: https://www.wireshark.org/security/wnpa-sec-2021-21.html NOTE: https://gitlab.com/wireshark/wireshark/-/merge_requests/5429 CVE-2021-45884 (In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based a ...) -- cgit v1.2.3