diff --git a/wireshark-initialize-point-in-end_string.patch b/wireshark-initialize-point-in-end_string.patch new file mode 100644 index 0000000000000000000000000000000000000000..29cf453ac87befcc0c9fa6c6038294d815d2c30f --- /dev/null +++ b/wireshark-initialize-point-in-end_string.patch @@ -0,0 +1,53 @@ +From 8862151190b333c938a47fbbe51b0a611607af7d Mon Sep 17 00:00:00 2001 +From: lingsheng +Date: Mon, 2 Nov 2020 16:01:57 +0800 +Subject: [PATCH] initialize point in end_string + +--- + epan/version_info.c | 2 +- + version_info.c | 2 +- + wiretap/version_info.c | 2 +- + 3 files changed, 3 insertions(+), 3 deletions(-) + +diff --git a/epan/version_info.c b/epan/version_info.c +index 6c80bd9..7e979d8 100644 +--- a/epan/version_info.c ++++ b/epan/version_info.c +@@ -47,7 +47,7 @@ + static void + end_string(GString *str) + { +- size_t point; ++ size_t point = 0; + char *p, *q; + + point = str->len; +diff --git a/version_info.c b/version_info.c +index 6c80bd9..7e979d8 100644 +--- a/version_info.c ++++ b/version_info.c +@@ -47,7 +47,7 @@ + static void + end_string(GString *str) + { +- size_t point; ++ size_t point = 0; + char *p, *q; + + point = str->len; +diff --git a/wiretap/version_info.c b/wiretap/version_info.c +index 6c80bd9..7e979d8 100644 +--- a/wiretap/version_info.c ++++ b/wiretap/version_info.c +@@ -47,7 +47,7 @@ + static void + end_string(GString *str) + { +- size_t point; ++ size_t point = 0; + char *p, *q; + + point = str->len; +-- +2.23.0 + diff --git a/wireshark.spec b/wireshark.spec index 19d421b73240ee5cb818e866a26b0a3f4d263d0b..7230542659d513000976127e1cfc10ec6de93cc5 100644 --- a/wireshark.spec +++ b/wireshark.spec @@ -1,6 +1,6 @@ Name: wireshark Version: 2.6.2 -Release: 12 +Release: 13 Epoch: 1 Summary: Network traffic analyzer License: GPL+ @@ -43,6 +43,7 @@ Patch6028: CVE-2020-15466.patch Patch6029: CVE-2018-16056.patch Patch6030: CVE-2020-25862.patch Patch6031: CVE-2020-25863.patch +Patch6032: wireshark-initialize-point-in-end_string.patch Requires(pre): shadow-utils Requires(post): systemd-udev @@ -149,6 +150,9 @@ getent group usbmon >/dev/null || groupadd -r usbmon %{_mandir}/man?/* %changelog +* Mon Nov 02 2020 lingsheng - 2.6.2-13 +- Fix use-of-uninitialized-value in end_string + * Wed Oct 21 2020 wangxiao - 2.6.2-12 - Type:cves - ID: CVE-2020-25862 CVE-2020-25863