更新日誌 |
The following vulnerabilities have been fixed: Bazaar dissector infinite loop. DOF dissector read overflow. DHCP dissector read overflow. SoulSeek dissector infinite loop. DNS dissector infinite loop. DICOM dissector infinite loop. openSAFETY dissector memory exhaustion. BT L2CAP dissector divide by zero. MSNIP dissector crash. ROS dissector crash. RGMP dissector crash. IPv6 dissector crash. The following bugs have been fixed: DICOM dissection error. Qt: drag & drop of one column header in PacketList moves other columns. Can not export captured DICOM objects in version 2.2.5. False complain about bad checksum of ICMP extension header. LibFuzzer: ISUP dissector bug (isup.number_different_meaning). Dissector Bug, protocol BT ATT. Wireshark dispalys RRCConnectionReestablishmentRejectRRCConnectionReestablishmentReject in Info column. UBSAN: shift exponent 105 is too large for 32-bit type int in packet-ositp.c:551:79. UBSAN: shift exponent -77 is negative in packet-netflow.c:7717:23. UBSAN: shift exponent 1959 is too large for 32-bit type int in packet-sigcomp.c:2128:28. UBSAN: shift exponent 63 is too large for 32-bit type guint32 (aka unsigned int) in packet-rtcp.c:917:24. UBSAN: shift exponent 70 is too large for 64-bit type guint64 (aka unsigned long) in dwarf.c:42:43. UBSAN: shift exponent 32 is too large for 32-bit type int in packet-xot.c:260:23. UBSAN: shift exponent -5 is negative in packet-sigcomp.c:1722:36. UBSAN: index 2049 out of bounds for type char [2049] in packet-quakeworld.c:134:5. UBSAN: shift exponent 35 is too large for 32-bit type int in packet-netsync.c:467:25. UBSAN: shift exponent 32 is too large for 32-bit type int in packet-sigcomp.c:3857:24. [oss-fuzz] ASAN: stack-use-after-return epan/dissectors/packet-ieee80211.c:14341:23 in add_tagged_field. Welcome screen invalid capture filter wihtout WinPcap installed causes runtime error. SMB protocol parser does not parse SMB_COM_TRANSACTION2_SECONDARY (0x33) command correctly. SIP packets with SDP marked as malformed. [oss-fuzz] UBSAN: index 8 out of bounds for type gboolean const[8] in packet-ieee80211-radiotap.c:1836:12. Crash on "Show packet bytes…" context menu item click. DNP3 dissector does not properly decode packed variations with prefixed qualifiers. Updated Protocol Support: Bazaar, BT ATT, BT L2CAP, DHCP, DICOM, DNP3, DNS, DOF, DWARF, ICMP, IEEE 802.11, IPv6, ISUP, LTE RRC, MSNIP, Netflow, Netsync, openSAFETY, OSITP, QUAKEWORLD, Radiotap, RGMP, ROS, RTCP, SIGCOMP, SMB, SoulSeek, and XOT. |