{"id":"SUSE-SU-2025:03294-1","summary":"Security update for wireshark","details":"This update for wireshark fixes the following issues:\n\nUpdate to version 4.2.13.\n\nSecurity issues fixed:\n \n- CVE-2025-9817: SSH dissector crash due to NULL pointer dereference when processing malformed packet traces\n  (bsc#1249090).\n\nNon-security issues fixed:\n\n- Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response.\n- Incorrectly parsed `application/x-www-form-urlencoded` key following a name-value byte sequence with no `=`.\n- DNP3 time stamp not working after epoch time (year 2038).\n- Bug in LZ77 decoder; reads a 16-bit length when it should read a 32-bit length.\n","modified":"2026-03-11T07:30:12.824898Z","published":"2025-09-22T14:10:47Z","related":["CVE-2025-9817"],"upstream":["CVE-2025-9817"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202503294-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9817"}],"affected":[{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP6","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.13-150600.18.26.1"}]}],"ecosystem_specific":{"binaries":[{"libwsutil15":"4.2.13-150600.18.26.1","wireshark":"4.2.13-150600.18.26.1","libwireshark17":"4.2.13-150600.18.26.1","libwiretap14":"4.2.13-150600.18.26.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:03294-1.json"}},{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.13-150600.18.26.1"}]}],"ecosystem_specific":{"binaries":[{"libwireshark17":"4.2.13-150600.18.26.1","libwiretap14":"4.2.13-150600.18.26.1","libwsutil15":"4.2.13-150600.18.26.1","wireshark":"4.2.13-150600.18.26.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:03294-1.json"}},{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP6","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.13-150600.18.26.1"}]}],"ecosystem_specific":{"binaries":[{"wireshark-devel":"4.2.13-150600.18.26.1","wireshark-ui-qt":"4.2.13-150600.18.26.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:03294-1.json"}},{"package":{"name":"wireshark","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/wireshark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.13-150600.18.26.1"}]}],"ecosystem_specific":{"binaries":[{"wireshark-devel":"4.2.13-150600.18.26.1","wireshark-ui-qt":"4.2.13-150600.18.26.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:03294-1.json"}},{"package":{"name":"wireshark","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/wireshark&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.13-150600.18.26.1"}]}],"ecosystem_specific":{"binaries":[{"wireshark-devel":"4.2.13-150600.18.26.1","wireshark-ui-qt":"4.2.13-150600.18.26.1","wireshark":"4.2.13-150600.18.26.1","libwireshark17":"4.2.13-150600.18.26.1","libwiretap14":"4.2.13-150600.18.26.1","libwsutil15":"4.2.13-150600.18.26.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:03294-1.json"}}],"schema_version":"1.7.5"}