diff --git a/SIGNATURES-2.4.4.txt b/SIGNATURES-2.4.4.txt deleted file mode 100644 index 8f16578..0000000 --- a/SIGNATURES-2.4.4.txt +++ /dev/null @@ -1,60 +0,0 @@ ------BEGIN PGP SIGNED MESSAGE----- -Hash: SHA512 - -wireshark-2.4.4.tar.xz: 28818372 bytes -SHA256(wireshark-2.4.4.tar.xz)=049a758e39422dcd536d7f75cebbfaa44e4f305d602bf22964d6459821126f58 -RIPEMD160(wireshark-2.4.4.tar.xz)=ee062bc380db3efce21640774bf6cb5c327b8b27 -SHA1(wireshark-2.4.4.tar.xz)=cefc8e6666ee2f73d7f96f2708d582c57abb486f - -Wireshark-win32-2.4.4.exe: 52697912 bytes -SHA256(Wireshark-win32-2.4.4.exe)=1f93c1df271aeaa60161d67abd9e17f48f07f1a7cfc84c3c09076be23b2a845e -RIPEMD160(Wireshark-win32-2.4.4.exe)=93ce703dc83c6cc0c23ade12a59bcbaa6088b8ba -SHA1(Wireshark-win32-2.4.4.exe)=1d14fb39f382909587ac9ce65477f1702570cb3a - -Wireshark-win64-2.4.4.exe: 57913704 bytes -SHA256(Wireshark-win64-2.4.4.exe)=f532b664921a317c151ef0fb2b4e7badcdb9ecd5a969d38bd54568a6a0a18c68 -RIPEMD160(Wireshark-win64-2.4.4.exe)=137f4225a15183bacc9c4c51522a99b624095c39 -SHA1(Wireshark-win64-2.4.4.exe)=e7890e6445118a9238cab51cf89407c6fdd2235d - -Wireshark-win64-2.4.4.msi: 47095808 bytes -SHA256(Wireshark-win64-2.4.4.msi)=38293816156d0aa51302e09fa2901a24913eb8e1b8cebee9bb90b318d85343f5 -RIPEMD160(Wireshark-win64-2.4.4.msi)=5b50bc5d30dad6f5e9eac8539da57c373f5c291d -SHA1(Wireshark-win64-2.4.4.msi)=70c0be5ff3d5d61428e7b07885a979d12e82ea6b - -Wireshark-win32-2.4.4.msi: 41943040 bytes -SHA256(Wireshark-win32-2.4.4.msi)=0407314ae45c391ca6cccddf428b8f452e6dbbfee13143d4cb178f643e8a5a8b -RIPEMD160(Wireshark-win32-2.4.4.msi)=22b168509f5bf9e8df2013aed781686ad89959b8 -SHA1(Wireshark-win32-2.4.4.msi)=003c2d7c3670b19b4397fc9855683e65ea12ea56 - -WiresharkPortable_2.4.4.paf.exe: 45378496 bytes -SHA256(WiresharkPortable_2.4.4.paf.exe)=4c6c0481ed216e797351fc38ba63754e37ac4cb2686595204f9be00d3b5dd4bb -RIPEMD160(WiresharkPortable_2.4.4.paf.exe)=773aa2c4fc2cd4126fd3da06da3066c27e45cd79 -SHA1(WiresharkPortable_2.4.4.paf.exe)=f484dd8d2bba9ccaefe187c0e50f30c231141bce - -Wireshark 2.4.4 Intel 64.dmg: 35240389 bytes -SHA256(Wireshark 2.4.4 Intel 64.dmg)=eb6d9a304b2697a90f267bd8734926a9fe37939aab8394a550cd4c272dd15e11 -RIPEMD160(Wireshark 2.4.4 Intel 64.dmg)=9cdf3614de288ae38170fae1d540bb3b874f997b -SHA1(Wireshark 2.4.4 Intel 64.dmg)=c1e169fbf3797a082b638cd8415d20f63d476131 - -You can validate these hashes using the following commands (among others): - - Windows: certutil -hashfile Wireshark-win64-x.y.z.exe SHA256 - Linux (GNU Coreutils): sha256sum wireshark-x.y.z.tar.xz - macOS: shasum -a 256 "Wireshark x.y.z Intel 64.dmg" - Other: openssl sha256 wireshark-x.y.z.tar.xz ------BEGIN PGP SIGNATURE----- - -iQIzBAEBCgAdFiEEWlrbp9vqbD+HIk8ZgiRKeOb+ruoFAlpXv64ACgkQgiRKeOb+ -ruqbgxAA3QnAr+1jKvBZUCApOSPxe/Hfz3MUoVBdnhj/bCDyAjACRLfRf91ODXPL -KGIt6d33W9N/FyK4M+6woYNHNdBiRW1UUuCsby1Z/0vdZ/LAtwJz6IeqNFS+g3Co -jVMVYBGLivSfwi0ZJWEiP1VILe2vKlUmAfgU5CTgtHrAHMTtrdvZIuzjnMLPNNqZ -1CYA7130Rda2pRWXbZWtgNf10VyRorpcMJ1y6ADZzm66GOJUQ585k0JCYgmLARPJ -1gy/VROrISMkVXETJnw6mR5pnSoqSoUrzz7QJoaDBDHXQugWhdLBDjKAcYTxQDZK -jcpDzPzXVeMF2l6LG+B0zDNzfPhAZHA5E9RRNew1Gth+bhC5UYV4+KW59Ovu3i/e -PfYWjUUmctzsOmibk3icf1PY5b6VqBNC9LMfnhmn/wg/uFDRwBWVe8pyvZCl7TVy -W+Y/YF6buB1L2aacKMmCyM8Gxptd+Tp3gnYrEInUVof+SsLulLrEM83dBEjvT3zr -Bxuv/47ZLSFmKv51/jj/3zNQ7NX3IYJbLTwWdGUsQE8ue2VBKE7mgLmvbtaRpAEh -5z18cPVMzdba7ufYGVt4ZuXR4sWrWBjVsaXWyjhGZxVygR/l0feVm8kcCufVJb4C -jNsdTLruH0Z6P9AuVPFf/ebgbARBytPfQI1zSBwM2NyCDKAwMno= -=uhIZ ------END PGP SIGNATURE----- diff --git a/SIGNATURES-2.4.5.txt b/SIGNATURES-2.4.5.txt new file mode 100644 index 0000000..a1e54b5 --- /dev/null +++ b/SIGNATURES-2.4.5.txt @@ -0,0 +1,60 @@ +-----BEGIN PGP SIGNED MESSAGE----- +Hash: SHA512 + +wireshark-2.4.5.tar.xz: 28836740 bytes +SHA256(wireshark-2.4.5.tar.xz)=b3b2ec29fba0f4a3a590438abe4054e56f19108d440fc2d61492db9d8ff16fd7 +RIPEMD160(wireshark-2.4.5.tar.xz)=f14cbb589a4fbf42f2420a34f2e98a2b274641e6 +SHA1(wireshark-2.4.5.tar.xz)=c49dfaba0a62d9e3f8ecda5e148f19cba9800900 + +Wireshark-win32-2.4.5.exe: 52716272 bytes +SHA256(Wireshark-win32-2.4.5.exe)=31687c3c0f9e7c2c0ce610db5c659680083d7204c5fbda4a98fb439a86c90011 +RIPEMD160(Wireshark-win32-2.4.5.exe)=68f6b32d6bef1e789dd4783229c7974026986d1f +SHA1(Wireshark-win32-2.4.5.exe)=0825f8d3525b109c55a4c8fb7fc249043d9b822c + +Wireshark-win64-2.4.5.exe: 57909112 bytes +SHA256(Wireshark-win64-2.4.5.exe)=867338819182ba636e1b741e87d60f1b06661138c2614db1253f1c75c17ae68c +RIPEMD160(Wireshark-win64-2.4.5.exe)=5f8040361904c6317cac57ae48884182dcd66172 +SHA1(Wireshark-win64-2.4.5.exe)=273d4395d9fc6323f4618884ccc46ad640bebb53 + +Wireshark-win64-2.4.5.msi: 47079424 bytes +SHA256(Wireshark-win64-2.4.5.msi)=201b6b9f4b9f15459287286809daba2d68464aa89320c1d676db565224e8b2ae +RIPEMD160(Wireshark-win64-2.4.5.msi)=700ab32ebb8e72999cf8916b53a3fb71ce279ca6 +SHA1(Wireshark-win64-2.4.5.msi)=7408105a82218aa1d9c4c9ce855738403734f230 + +Wireshark-win32-2.4.5.msi: 41967616 bytes +SHA256(Wireshark-win32-2.4.5.msi)=8a1fff845e5b51c1778f42e43d715a1f41943fd7bced32424eed7eb0b295abf8 +RIPEMD160(Wireshark-win32-2.4.5.msi)=7eb658336b6679a3b828d1a54b29acc0a2f6e162 +SHA1(Wireshark-win32-2.4.5.msi)=11d8b499d128cf64c7226fb0e76fc44354008d60 + +WiresharkPortable_2.4.5.paf.exe: 45373920 bytes +SHA256(WiresharkPortable_2.4.5.paf.exe)=b2bb1d15a0c5cbd9fd168688b24cf0aff2445a005641adcae531aa3a605a5964 +RIPEMD160(WiresharkPortable_2.4.5.paf.exe)=5a0d230438eae0d33f3410fdf165c885712b96d7 +SHA1(WiresharkPortable_2.4.5.paf.exe)=8341f112a2bc90256d2a5b4a6a01655d50c381f5 + +Wireshark 2.4.5 Intel 64.dmg: 42004449 bytes +SHA256(Wireshark 2.4.5 Intel 64.dmg)=028592817849f180f4014288a9566910e4ab508cb3b53a9721c9c667379acd15 +RIPEMD160(Wireshark 2.4.5 Intel 64.dmg)=0c6adbb0068ad4e87af17397a7cfeb33ed80db69 +SHA1(Wireshark 2.4.5 Intel 64.dmg)=7b6bc07482f7ef506a559a922d413e2e1989d796 + +You can validate these hashes using the following commands (among others): + + Windows: certutil -hashfile Wireshark-win64-x.y.z.exe SHA256 + Linux (GNU Coreutils): sha256sum wireshark-x.y.z.tar.xz + macOS: shasum -a 256 "Wireshark x.y.z Intel 64.dmg" + Other: openssl sha256 wireshark-x.y.z.tar.xz +-----BEGIN PGP SIGNATURE----- + +iQIzBAEBCgAdFiEEWlrbp9vqbD+HIk8ZgiRKeOb+ruoFAlqQfH4ACgkQgiRKeOb+ +rur5tBAAoGElt+RqtABqCauP4bEksWtXfSkoR+aJbYm+VKaHwQgdKDBE6MmJEa+7 +5ZxSe4nmtES/t9wPFmSD8g3fAn5a5zeL6O5pX8mmktxxqvisP8VuVJZZ7+zkoOQI +5GgU8S5NvYWFL1EqAjNbB0aTKpdEm/x5m5X9q3Y24w7C2gPL2kPo2QeCvviYJgT4 +Z725buE6gQ3rMPkYSieImOcDKqUVvPDwbz76xVrFYW251cSMUzIQTTbeQs+peNsq +FUpq/atnZR5ZUS73fbcgQgyulEEEgtVYihun/phJt3CKLw46zaitiMdaYl7Bt0HJ +pt2XpQuK0/diO2it4wDdV1QZ/DIMxnL3ty5r3rT3XqDT8OFZkecOhji8fqTKs5nn +WJH+7agG24MEvOmBn/x6QEp8Tm3T0dRZe5O5Z6XnMJwH1deqBDMaRK0ndCb7QXKW +ww1oS8AkxfB3+9WlcBpMWOQOCaoHmabCugdKubHzrFBYe/ETx42UuVr/1swphVpU +VCgpI/3uMV/JTEWKjMgod1h880j5y2ZUSF8z20bitjdJxYEeAhww3V58+4zFSnGc +QsHeSD1UAl5DzVkkycA3lwHC40XHvB1G85jN4nEVui4IM5NdCEYxaEm6onCVbqa+ +2wt9iv1Djun6aGqf0zHeMtffxzjyyTINLL4XqYgImkGYXC9/zKE= +=HIJo +-----END PGP SIGNATURE----- diff --git a/wireshark-2.4.4.tar.xz b/wireshark-2.4.4.tar.xz deleted file mode 100644 index 41733f5..0000000 --- a/wireshark-2.4.4.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:049a758e39422dcd536d7f75cebbfaa44e4f305d602bf22964d6459821126f58 -size 28818372 diff --git a/wireshark-2.4.5.tar.xz b/wireshark-2.4.5.tar.xz new file mode 100644 index 0000000..64455c2 --- /dev/null +++ b/wireshark-2.4.5.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:b3b2ec29fba0f4a3a590438abe4054e56f19108d440fc2d61492db9d8ff16fd7 +size 28836740 diff --git a/wireshark.changes b/wireshark.changes index c2f61bd..8cb77d3 100644 --- a/wireshark.changes +++ b/wireshark.changes @@ -1,3 +1,28 @@ +------------------------------------------------------------------- +Sat Feb 24 10:04:01 UTC 2018 - astieger@suse.com + +- Wireshark 2.4.5: + This release fixes minor vulnerabilities that could be used to + trigger dissector crashes or cause dissectors to go into large + infinite loops by making Wireshark read specially crafted + packages from the network or capture files (bsc#1082692): + * CVE-2018-7335: The IEEE 802.11 dissector could crash + * CVE-2018-7321, CVE-2018-7322, CVE-2018-7323, CVE-2018-7324, + CVE-2018-7325, CVE-2018-7326, CVE-2018-7327, CVE-2018-7328, + CVE-2018-7329, CVE-2018-7330, CVE-2018-7331, CVE-2018-7332, + CVE-2018-7333, CVE-2018-7421: Multiple dissectors could go + into large infinite loops + * CVE-2018-7334: The UMTS MAC dissector could crash + * CVE-2018-7337: The DOCSIS dissector could crash + * CVE-2018-7336: The FCP dissector could crash + * CVE-2018-7320: The SIGCOMP dissector could crash + * CVE-2018-7420: The pcapng file parser could crash + * CVE-2018-7417: The IPMI dissector could crash + * CVE-2018-7418: The SIGCOMP dissector could crash + * CVE-2018-7419: The NBAP disssector could crash + * Further bug fixes and updated protocol support as listed in: + https://www.wireshark.org/docs/relnotes/wireshark-2.4.5.html + ------------------------------------------------------------------- Fri Jan 12 19:38:34 UTC 2018 - astieger@suse.com diff --git a/wireshark.spec b/wireshark.spec index 0162e90..7d670a0 100644 --- a/wireshark.spec +++ b/wireshark.spec @@ -36,7 +36,7 @@ %bcond_with geoip %endif Name: wireshark -Version: 2.4.4 +Version: 2.4.5 Release: 0 Summary: A Network Traffic Analyser License: GPL-2.0+ AND GPL-3.0+