Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian DSA-2871-1 Critical: Wireshark DoS And Buffer Overflow

debian
Calendar Grey March 10, 2014
Debian Logo
Various security flaws in Wireshark that could result in Denial of Service and execution of arbitrary code have been addressed for users on Debian.
Multiple vulnerabilities were discovered in Wireshark: CVE-2014-2281

Summary

Multiple vulnerabilities were discovered in Wireshark:

CVE-2014-2281

Moshe Kaplan discovered that the NFS dissector could be crashed,
resulting in denial of service.

CVE-2014-2283

It was discovered that the RLC dissector could be crashed, resulting
in denial of service.

CVE-2014-2299

Wesley Neelen discovered a buffer overflow in the MPEG file parser,
which could lead to the execution of arbitrary code.

For the oldstable distribution (squeeze), these problems have been fixed in
version 1.2.11-6+squeeze14.

For the stable distribution (wheezy), these problems have been fixed in
version 1.8.2-5wheezy10.

For the unstable distribution (sid), these problems have been fixed in
version 1.10.6-1.

We recommend that you upgrade your wireshark packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/






Severity
critical
Lowest
Low
Medium
High
Critical

Package: wireshark
CVE ID: CVE-2014-2281 CVE-2014-2283 CVE-2014-2299

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here