Search CVE reports


Toggle filters

391 – 400 of 893 results


CVE-2017-9350

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9349

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9348

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9347

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9346

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9345

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9344

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-9343

Medium priority
Fixed

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.

1 affected package

wireshark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-6887

Low priority

Some fixes available 3 of 111

A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100"...

12 affected packages

dcraw, darktable, exactimage, kodi, rawtherapee...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Vulnerable
flphoto Not in release Not in release Not in release Not in release Not in release
freeimage Not affected Not affected Not affected Not affected Not affected
graphicsmagick Not affected Not affected Not affected Not affected Not affected
rawstudio Not in release Not in release Not in release Not in release Not in release
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages

CVE-2017-6886

Low priority

Some fixes available 3 of 109

An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.

12 affected packages

darktable, flphoto, dcraw, exactimage, kodi...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
flphoto Not in release Not in release Not in release Not in release Not in release
dcraw Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
exactimage Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Not in release Ignored
rawstudio Not in release Not in release Not in release Not in release Not in release
freeimage Not affected Not affected Not affected Not affected Not affected
graphicsmagick Not affected Not affected Not affected Not affected Not affected
xbmc Not in release Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages