Log

AVG-1511 edited at 30 Jan 2021 20:05:38
Severity
- Unknown
+ Medium
CVE-2020-29652 edited at 30 Jan 2021 20:05:38
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A null pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
References
+ https://groups.google.com/g/golang-announce/c/ouZIlBimOsE
+ https://go-review.googlesource.com/c/crypto/+/278852
+ https://go.googlesource.com/crypto/+/8b5274cf687fd9316b4108863654cc57385531e8%5E%21/#F0
Notes
AVG-1511 created at 30 Jan 2021 20:03:25
Packages
+ golang-golang-x-crypto
Issues
+ CVE-2020-29652
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 0.0.20200303-2
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes
CVE-2020-29652 created at 30 Jan 2021 20:03:25
AVG-1504 edited at 29 Jan 2021 22:34:56
Status
- Vulnerable
+ Fixed
Fixed
+ 6.8.1-2
AVG-1510 edited at 29 Jan 2021 21:52:16
Status
- Vulnerable
+ Fixed
Fixed
+ 3.4.3-1
AVG-1510 edited at 29 Jan 2021 20:27:49
Severity
- Medium
+ Low
CVE-2021-22174 edited at 29 Jan 2021 20:27:49
Severity
- Medium
+ Low
CVE-2021-22173 edited at 29 Jan 2021 20:27:45
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A memory leak leading to denial of service has been found in Wireshark before 3.4.3, in the USB HID dissector. It can be triggered by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
References
+ https://www.wireshark.org/security/wnpa-sec-2021-01
+ https://gitlab.com/wireshark/wireshark/-/issues/17124
+ https://gitlab.com/wireshark/wireshark/-/merge_requests/1812
Notes
AVG-1510 edited at 29 Jan 2021 20:26:51
Severity
- Unknown
+ Medium
CVE-2021-22174 edited at 29 Jan 2021 20:26:51
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ A denial of service has been found in Wireshark before 3.4.3, in the USB HID dissector. It can be triggered by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
References
+ https://www.wireshark.org/security/wnpa-sec-2021-02
+ https://gitlab.com/wireshark/wireshark/-/issues/17165
+ https://gitlab.com/wireshark/wireshark/-/merge_requests/1849
Notes
AVG-1510 created at 29 Jan 2021 20:24:05
Packages
+ wireshark-cli
Issues
+ CVE-2021-22173
+ CVE-2021-22174
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 3.4.2-1
Fixed
Ticket
Advisory qualified
+ Yes
References
+ https://www.wireshark.org/security/wnpa-sec-2021-01
+ https://www.wireshark.org/security/wnpa-sec-2021-02
Notes
CVE-2021-22174 created at 29 Jan 2021 20:24:05
AVG-1510 created at 29 Jan 2021 20:24:05
Packages
+ wireshark-cli
Issues
+ CVE-2021-22173
+ CVE-2021-22174
Status
+ Vulnerable
Severity
+ Unknown
Affected
+ 3.4.2-1
Fixed
Ticket
Advisory qualified
+ Yes
References
+ https://www.wireshark.org/security/wnpa-sec-2021-01
+ https://www.wireshark.org/security/wnpa-sec-2021-02
Notes
CVE-2021-22173 created at 29 Jan 2021 20:24:05
AVG-1509 created at 29 Jan 2021 20:19:25
Packages
+ linux-lts
Issues
+ CVE-2021-3347
Status
+ Vulnerable
Severity
+ Medium
Affected
+ 5.4.93-2
Fixed
Ticket
Advisory qualified
+ Yes
References
Notes