ELA-839-1 wireshark security update

multiple vulnerabilities

2023-04-29
Packagewireshark
Version2.6.20-0+deb9u5 (stretch)
Related CVEs CVE-2023-1161 CVE-2023-1992 CVE-2023-1993 CVE-2023-1994


Several vulnerabilities were fixed in the network traffic analyzer Wireshark.

CVE-2023-1161

ISO 15765 dissector crash

CVE-2023-1992

RPCoRDMA dissector crash

CVE-2023-1993

LISP dissector large loop vulnerability

CVE-2023-1994

GQUIC dissector crash


For Debian 9 stretch, these problems have been fixed in version 2.6.20-0+deb9u5.

We recommend that you upgrade your wireshark packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.