Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Debian: DSA-1414-1 Moderate Security Alert for Wireshark Issue

debian
Calendar Grey November 27, 2007
Scroller Debian
- ------------------------------------------------------------------------Debian Security Advisory D
Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to denial of service or the execution of arbitrary code

Summary


Stefan Esser discovered a buffer overflow in the SSL dissector.
"Fabiodds" discovered a buffer overflow in the iSeries trace
dissector.

CVE-2007-6117

A programming error was discovered in the HTTP dissector, which may
lead to denial of service.

CVE-2007-6118

The MEGACO dissector could be tricked into ressource exhaustion.

CVE-2007-6120

The Bluetooth SDP dissector could be tricked into an endless loop.

CVE-2007-6121

The RPC portmap dissector could be tricked into dereferencing
a NULL pointer.

For the stable distribution (etch), these problems have been fixed
in version 0.99.4-5.etch.1. Updates packages for sparc will be provided
later.

For the old stable distribution (sarge), these problems have been
fixed in version 0.10.10-2sarge10. (In Sarge Wireshark used to be
called Ethereal). Updates packages for sparc and m68k will be provided
later.

We recommend that you upgrade your wireshark/ethereal packages.

Upgrade instructions
- --------...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.