{"affected":[{"ecosystem_specific":{"binaries":[{"libwireshark9":"2.4.7-3.3.4","libwiretap7":"2.4.7-3.3.4","libwscodecs1":"2.4.7-3.3.4","libwsutil8":"2.4.7-3.3.4","wireshark":"2.4.7-3.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15","name":"wireshark","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.7-3.3.4"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wireshark-devel":"2.4.7-3.3.4","wireshark-ui-qt":"2.4.7-3.3.4"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","name":"wireshark","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.4.7-3.3.4"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for wireshark fixes vulnerabilities that could be\nused to trigger dissector crashes or cause dissectors to go into large infinite\nloops by making Wireshark read specially crafted packages from the network or\ncapture files (bsc#1094301).\n\nThis includes:\n\n- CVE-2018-11356: DNS dissector crash \n- CVE-2018-11357: Multiple dissectors could consume excessive memory \n- CVE-2018-11358: Q.931 dissector crash\n- CVE-2018-11359: The RRC dissector and other dissectors could crash\n- CVE-2018-11360: GSM A DTAP dissector crash \n- CVE-2018-11362: LDSS dissector crash \n","id":"SUSE-SU-2018:1988-1","modified":"2018-07-19T07:32:17Z","published":"2018-07-19T07:32:17Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20181988-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094301"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11362"}],"related":["CVE-2018-11356","CVE-2018-11357","CVE-2018-11358","CVE-2018-11359","CVE-2018-11360","CVE-2018-11362"],"summary":"Security update for wireshark","upstream":["CVE-2018-11356","CVE-2018-11357","CVE-2018-11358","CVE-2018-11359","CVE-2018-11360","CVE-2018-11362"]}