<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2024-0175</id>
    <title>An update for wireshark is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2024-06-28 03:57:38"/>
    <updated date="2024-06-28 03:57:38"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-4855" id="CVE-2024-4855" title="CVE-2024-4855 Base Score: 3.6 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-4853" id="CVE-2024-4853" title="CVE-2024-4853 Base Score: 3.6 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-4854" id="CVE-2024-4854" title="CVE-2024-4854 Base Score: 6.4 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

Use after free issue in editcap could cause denial of service via crafted capture file (CVE-2024-4855)

Memory handling issue in editcap could cause denial of service via crafted capture file (CVE-2024-4853)

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file (CVE-2024-4854)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="wireshark">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="wireshark" version="3.6.14" release="8.hce2">
          <filename>wireshark-3.6.14-8.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="wireshark-devel" version="3.6.14" release="8.hce2">
          <filename>wireshark-devel-3.6.14-8.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="wireshark-help" version="3.6.14" release="8.hce2">
          <filename>wireshark-help-3.6.14-8.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="wireshark" version="3.6.14" release="8.hce2">
          <filename>wireshark-3.6.14-8.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="wireshark-devel" version="3.6.14" release="8.hce2">
          <filename>wireshark-devel-3.6.14-8.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="wireshark-help" version="3.6.14" release="8.hce2">
          <filename>wireshark-help-3.6.14-8.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
