From f830f94cce13fdd7cc7b3748ea3dd55eaeabb414aa8828798f6c90a718dc8b32 Mon Sep 17 00:00:00 2001 From: Andreas Stieger Date: Fri, 12 Oct 2018 16:15:07 +0000 Subject: [PATCH] Accepting request 641680 from home:AndreasStieger:branches:network:utilities Wireshark 2.6.4 (bsc#1111647) * CVE-2018-18227: MS-WSP dissector crash (wnpa-sec-2018-47) * CVE-2018-18226: Steam IHS Discovery dissector memory leak (wnpa-sec-2018-48) * CVE-2018-18225: CoAP dissector crash (wnpa-sec-2018-49) * CVE-2018-12086: OpcUA dissector crash (wnpa-sec-2018-50) OBS-URL: https://build.opensuse.org/request/show/641680 OBS-URL: https://build.opensuse.org/package/show/network:utilities/wireshark?expand=0&rev=263 --- SIGNATURES-2.6.3.txt | 60 ------------------------------------------ SIGNATURES-2.6.4.txt | 60 ++++++++++++++++++++++++++++++++++++++++++ wireshark-2.6.3.tar.xz | 3 --- wireshark-2.6.4.tar.xz | 3 +++ wireshark.changes | 11 ++++++++ wireshark.spec | 2 +- 6 files changed, 75 insertions(+), 64 deletions(-) delete mode 100644 SIGNATURES-2.6.3.txt create mode 100644 SIGNATURES-2.6.4.txt delete mode 100644 wireshark-2.6.3.tar.xz create mode 100644 wireshark-2.6.4.tar.xz diff --git a/SIGNATURES-2.6.3.txt b/SIGNATURES-2.6.3.txt deleted file mode 100644 index e6e27c9..0000000 --- a/SIGNATURES-2.6.3.txt +++ /dev/null @@ -1,60 +0,0 @@ ------BEGIN PGP SIGNED MESSAGE----- -Hash: SHA512 - -wireshark-2.6.3.tar.xz: 28384004 bytes -SHA256(wireshark-2.6.3.tar.xz)=d158a8a626dc0997a826cf12b5316a3d393fb9f93d84cc86e75b212f0044a3ec -RIPEMD160(wireshark-2.6.3.tar.xz)=74a558e7a004c64ff118870d525025beda4a665d -SHA1(wireshark-2.6.3.tar.xz)=d239fd091d59968ac8a1b42b28e61aeef09c20b7 - -Wireshark-win64-2.6.3.exe: 60001560 bytes -SHA256(Wireshark-win64-2.6.3.exe)=40701d569f75ba08bd3fb9d79e6841095d6d3001e5d8f1e9f50c996bcf0657ff -RIPEMD160(Wireshark-win64-2.6.3.exe)=d2068b7c1d7a95a2d57470ae7831fd988b5183a6 -SHA1(Wireshark-win64-2.6.3.exe)=800bc4d9b6a8b1d96844e706863f0e636839b5cc - -Wireshark-win32-2.6.3.exe: 54282456 bytes -SHA256(Wireshark-win32-2.6.3.exe)=3b1519d04d982220941a9fff03af74110b68fbe7f1cedd79ad3f097593c5f456 -RIPEMD160(Wireshark-win32-2.6.3.exe)=b86dc149ca96f7e1efca3e6c7439ae41d9553e19 -SHA1(Wireshark-win32-2.6.3.exe)=cad7ba639d2e7f538eee4b771ed3e6f1c763da25 - -Wireshark-win64-2.6.3.msi: 49381376 bytes -SHA256(Wireshark-win64-2.6.3.msi)=93e31bc9ec4871475d7ca1c608507e6b9815f7a767cd10aa9cc33dbd078fbd1c -RIPEMD160(Wireshark-win64-2.6.3.msi)=dd4f223c7f471fc482c9f1fc80de1a805c2bd375 -SHA1(Wireshark-win64-2.6.3.msi)=78e267546f13596ffedd2d94c6a58c0b99e7dec9 - -Wireshark-win32-2.6.3.msi: 43741184 bytes -SHA256(Wireshark-win32-2.6.3.msi)=063232cde36dbce1a8a73abf26aacec94798b3d42af4cd423a30c6cc6834c762 -RIPEMD160(Wireshark-win32-2.6.3.msi)=9270a9c45c862891c88a07961bbb1a247dee5909 -SHA1(Wireshark-win32-2.6.3.msi)=ad302be6a55731d676756d5dc60b6de355f311ff - -WiresharkPortable_2.6.3.paf.exe: 37485464 bytes -SHA256(WiresharkPortable_2.6.3.paf.exe)=419a784a070adbb261991eada51e489f704e13808fcd7516b0edb5c6d91a8480 -RIPEMD160(WiresharkPortable_2.6.3.paf.exe)=fe4926b7abb83a28bf327de345f2eca10bcc510d -SHA1(WiresharkPortable_2.6.3.paf.exe)=6218dff001e2e1ac8a733f8a82e878622b9647fc - -Wireshark 2.6.3 Intel 64.dmg: 169056690 bytes -SHA256(Wireshark 2.6.3 Intel 64.dmg)=5f919d58ba1286631f2a878d7ec5acf430680f57d3d630d76e096077b4494418 -RIPEMD160(Wireshark 2.6.3 Intel 64.dmg)=4e35d92b01e15f2500b6f7e4ad8f1225a518c183 -SHA1(Wireshark 2.6.3 Intel 64.dmg)=5809c04cdda26e124027bb55d318c99dfd61b008 - -You can validate these hashes using the following commands (among others): - - Windows: certutil -hashfile Wireshark-win64-x.y.z.exe SHA256 - Linux (GNU Coreutils): sha256sum wireshark-x.y.z.tar.xz - macOS: shasum -a 256 "Wireshark x.y.z Intel 64.dmg" - Other: openssl sha256 wireshark-x.y.z.tar.xz ------BEGIN PGP SIGNATURE----- - -iQIzBAEBCgAdFiEEWlrbp9vqbD+HIk8ZgiRKeOb+ruoFAluG5dQACgkQgiRKeOb+ -rupuhhAA7tWYs068DvPgUzIFrd58A1RogpoAdANICaRgqNJLpVsIR/5SiF2RU1oO -KFCgy83qufQcokGNS77cX3lrnCP0T6Q1QY1CpS/ZiLAxBk8e+rQNKqn1/Z34Tsso -T6EbMZqEZA3HAerDGlwsgy5AuOcOLWCdBqMC6bwbF4zd0Vj/q9x5Io88sKJjbX7z -gsMiSM3A5tFdmc+/HQqqAg6+u77fRih6w8pBGSQDEj7NEYhQYa3y0RdjF/6o9YQt -Q1ISmCpGcpdr8cE/+uwTz7CaKtQz9FkbpuG23ow1/vJDH1Qi5WSNrp5exhrCAZAk -ZY9Jy3cVviDDUao5gOHM67ytci171zslO+JcXweNiBSzdcP/tUAdmJBVUZSfTgeJ -bVyWCa4RRGRSSOCxGvaAKQKH/k50WK2lzvlh/4q9OI/yuuQVDobVwFdyHUIwZVOf -A8IwXuqGju8y9yjAmnMJUEYBdbXUuaPuocqgIs4vSOsOw+A2o10MLu50rAs0cvWi -40a/olOS7THk6dHuIHEARp/oGbMCfOFYJl9JdM/UFY1PU2cTvtFGhC2EYIFQYoKx -pTcJ1IXk4H6BDfU14sWud1lEONXCCqxunMqzd8LI5wpcTJ7dyjYkR770UpVhVYm4 -gwshi3OJoUGDd2O/uZdutfWr7G03/mp2eEcZQMj2NVB1zxaSmEE= -=kvMc ------END PGP SIGNATURE----- diff --git a/SIGNATURES-2.6.4.txt b/SIGNATURES-2.6.4.txt new file mode 100644 index 0000000..b1eebf6 --- /dev/null +++ b/SIGNATURES-2.6.4.txt @@ -0,0 +1,60 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +wireshark-2.6.4.tar.xz: 28218232 bytes +SHA256(wireshark-2.6.4.tar.xz)=a06b007e6343f148b8b93443b2fcfc9bb3204311cd268565d54d1b71660bc861 +RIPEMD160(wireshark-2.6.4.tar.xz)=719cab381d824672e0f5e4b1c7a20de8863b28a6 +SHA1(wireshark-2.6.4.tar.xz)=89ef68c2696b6b424cc65bb63a1be085fe7bd776 + +Wireshark-win32-2.6.4.exe: 53791520 bytes +SHA256(Wireshark-win32-2.6.4.exe)=e2a75ec989c8c9c00cd197be7f137707fbc924899fdae2e50e5515b27e7d0ed5 +RIPEMD160(Wireshark-win32-2.6.4.exe)=29f2145f3adbf6a3843ac8254e9f2f10f99f4a47 +SHA1(Wireshark-win32-2.6.4.exe)=0e24a5436e8fd67718395955526ed33a33602671 + +Wireshark-win64-2.6.4.exe: 59534280 bytes +SHA256(Wireshark-win64-2.6.4.exe)=3ca543a311a9ec3f9b2045768ead78af3acd19f8fa447aae9885712c5f8aaddb +RIPEMD160(Wireshark-win64-2.6.4.exe)=046e6a80423124a3f108dabafb15c4569806cd3c +SHA1(Wireshark-win64-2.6.4.exe)=dc591ec27efbbd2c8380977b54ea3bb098c9d7ba + +Wireshark-win32-2.6.4.msi: 43290624 bytes +SHA256(Wireshark-win32-2.6.4.msi)=20d280fc4b408f6a435e2dc79aefe0f37c82e0ccf46d83ad73eb946e024d5406 +RIPEMD160(Wireshark-win32-2.6.4.msi)=454e9c321db9f580f58768da5cbee20df2058c85 +SHA1(Wireshark-win32-2.6.4.msi)=0bbf4a9d9252b278377a36137c675fa3d0b84454 + +Wireshark-win64-2.6.4.msi: 48910336 bytes +SHA256(Wireshark-win64-2.6.4.msi)=ecfd6cd94b78312f7c195852d9cc0cb9d611795b566ccda7a9ada9579fd34007 +RIPEMD160(Wireshark-win64-2.6.4.msi)=73a7ad4248ed93b3035b17d6aa0b3e128249f8b4 +SHA1(Wireshark-win64-2.6.4.msi)=977725db376f9e81cc1bde7f7a307f87acdc2074 + +WiresharkPortable_2.6.4.paf.exe: 37024056 bytes +SHA256(WiresharkPortable_2.6.4.paf.exe)=68a7329733bc0a9ed6dd073bc25886863d7e22ab7cd75b2ae60899a044cad417 +RIPEMD160(WiresharkPortable_2.6.4.paf.exe)=6f19d28957c53b65de397795e5f5c2496d23b6a1 +SHA1(WiresharkPortable_2.6.4.paf.exe)=c79c09f4153d5eec24e985afac82021cbfc6a9a2 + +Wireshark 2.6.4 Intel 64.dmg: 168568106 bytes +SHA256(Wireshark 2.6.4 Intel 64.dmg)=3c347c3ffdbab2d7a358bb4a231e18ef730eb87175c80db7e2fd61b25e8a6d51 +RIPEMD160(Wireshark 2.6.4 Intel 64.dmg)=226997747055fcaff89d430762f7c16d06cbcce4 +SHA1(Wireshark 2.6.4 Intel 64.dmg)=cf32dcaf919b79b6d8cd35d22ca891d45540d787 + +You can validate these hashes using the following commands (among others): + + Windows: certutil -hashfile Wireshark-win64-x.y.z.exe SHA256 + Linux (GNU Coreutils): sha256sum wireshark-x.y.z.tar.xz + macOS: shasum -a 256 "Wireshark x.y.z Intel 64.dmg" + Other: openssl sha256 wireshark-x.y.z.tar.xz +-----BEGIN PGP SIGNATURE----- + +iQIzBAEBCgAdFiEEWlrbp9vqbD+HIk8ZgiRKeOb+ruoFAlu/zpcACgkQgiRKeOb+ +ruqhKQ//SZeNT+K8etgAeSMgyJT/3Mw9o65MyYALLocBAeNXhURY6IoQcWp5eBBX +5vYJE7WVEaDytk2ngYd9os8aOA8z59UdRDU/f77YgwxqXHn0Sa2IBsdCBlyRNbGI +5z4pGurfmYfy6QMDUgv3htP2ZLAuAHUABbElV2H5nObBWIpsCgqbRibANE0WOiKF +6cO9sUUlT29iINeRpIZVqpm34OzuI3itpXrwrZAguUfgKQQD2pcfzfScxtLELPsg +C2DJ8p947RVGbNLII16rWWFkH0FvIJoc7LISFoMI08GURfRKabYwO5OAtZ4Wp7Wx +j66Ozthtiewz9i8u+S535Hqisy5He6eZwuxlS9Yd5dWBCtXSzzrdvg0OfTGI9w0+ +s+Lr5MziG9z5Zj3gO9X2wM1p4O48uaEORysE4YsHMlBGYR6+YN91mNgPqMafmbqE +/gBn/X//dssvcNua92I3W6pxJmdtw38ToaiVMp+tUKVDrk3BGzp4FmbX78fbYNxE +/9uJ4PTtCtbb7r9Z3v3BTgKyu2skkCVp8Z9ssKYUuOtac0JVHi3idgj9IxBvJSgA +2ZKbEsjtqoL5EgTb7+mxsXaX/Nc22fcfD9YNZSg/1+00pdEkmH4hsr8bjPiv3tKZ +E7p3SZiXFpAWrTpKfdByAxLCSzuS6TKAadVlfqX24ZDARbnBWPU= +=C5CQ +-----END PGP SIGNATURE----- diff --git a/wireshark-2.6.3.tar.xz b/wireshark-2.6.3.tar.xz deleted file mode 100644 index c2f7a54..0000000 --- a/wireshark-2.6.3.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:d158a8a626dc0997a826cf12b5316a3d393fb9f93d84cc86e75b212f0044a3ec -size 28384004 diff --git a/wireshark-2.6.4.tar.xz b/wireshark-2.6.4.tar.xz new file mode 100644 index 0000000..c441201 --- /dev/null +++ b/wireshark-2.6.4.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:a06b007e6343f148b8b93443b2fcfc9bb3204311cd268565d54d1b71660bc861 +size 28218232 diff --git a/wireshark.changes b/wireshark.changes index 1f5be8e..a47fff3 100644 --- a/wireshark.changes +++ b/wireshark.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Fri Oct 12 12:54:01 UTC 2018 - astieger@suse.com + +- Wireshark 2.6.4 (bsc#1111647): + * CVE-2018-18227: MS-WSP dissector crash (wnpa-sec-2018-47) + * CVE-2018-18226: Steam IHS Discovery dissector memory leak (wnpa-sec-2018-48) + * CVE-2018-18225: CoAP dissector crash (wnpa-sec-2018-49) + * CVE-2018-12086: OpcUA dissector crash (wnpa-sec-2018-50) +- Further bug fixes and updated protocol support as listed in: + https://www.wireshark.org/docs/relnotes/wireshark-2.6.4.html + ------------------------------------------------------------------- Wed Aug 29 20:29:12 UTC 2018 - astieger@suse.com diff --git a/wireshark.spec b/wireshark.spec index 22e975f..6b9a68e 100644 --- a/wireshark.spec +++ b/wireshark.spec @@ -37,7 +37,7 @@ %bcond_with lz4 %endif Name: wireshark -Version: 2.6.3 +Version: 2.6.4 Release: 0 Summary: A Network Traffic Analyser License: GPL-2.0-or-later AND GPL-3.0-or-later