package/wireshark: security bump to version 3.2.7
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Sat, 10 Oct 2020 20:06:46 +0000 (22:06 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Sun, 11 Oct 2020 17:00:17 +0000 (19:00 +0200)
commitd9521e04471fd3420b1b9fcb265425c3a49c574f
tree8b01493b0109df42bdca24629223845e21fcadbe
parentbbe7ef1922b42dd81d5c8015455f39eb5bdb2e1d
package/wireshark: security bump to version 3.2.7

- Fix CVE-2020-25862: In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and
  2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in
  epan/dissectors/packet-tcp.c by changing the handling of the invalid
  0xFFFF checksum.
- Fix CVE-2020-25863: In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and
  2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was
  addressed in epan/dissectors/packet-multipart.c by correcting the
  deallocation of invalid MIME parts.
- Fix CVE-2020-25866: In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13,
  the BLIP protocol dissector has a NULL pointer dereference because a
  buffer was sized for compressed (not uncompressed) messages. This was
  addressed in epan/dissectors/packet-blip.c by allowing reasonable
  compression ratios and rejecting ZIP bombs.

https://www.wireshark.org/docs/relnotes/wireshark-3.2.7.html

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/wireshark/wireshark.hash
package/wireshark/wireshark.mk