Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Scientific Linux: 2007-11-15 Low Severity Wireshark Update

Scientific Large Esm H446
Low: wireshark security and bug fix update
Date:         Thu, 15 Nov 2007 14:11:27 -0600
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for wireshark on SL4.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.

Synopsis:	Low: wireshark security and bug fix update
Issue date:	2007-11-15
CVE Names:	CVE-2007-3389 CVE-2007-3390 CVE-2007-3391
                 CVE-2007-3392 CVE-2007-3393

Several denial of service bugs were found in Wireshark's HTTP, iSeries, DCP
ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors. It was possible for
Wireshark to crash or stop responding if it read a malformed packet off the
network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392,
CVE-2007-3393)

Wireshark would interpret certain completion codes incorrectly when
dissecting IPMI traffic. Additionally, IPMI 2.0 packets would be reported
as malformed IPMI traffic.

SL 4.x

   SRPMS:
wireshark-0.99.6-EL4.1.src.rpm
   i386:
wireshark-0.99.6-EL4.1.i386.rpm
wireshark-gnome-0.99.6-EL4.1.i386.rpm
   x86_64:
wireshark-0.99.6-EL4.1.x86_64.rpm
wireshark-gnome-0.99.6-EL4.1.x86_64.rpm

-Connie Sieh
-Troy Dawson