Date: Tue, 20 Apr 2010 15:58:27 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: wireshark on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: wireshark security update Issue date: 2010-04-20 CVE Names: CVE-2009-2560 CVE-2009-2562 CVE-2009-2563 CVE-2009-3550 CVE-2009-3829 CVE-2009-4377 CVE-2010-0304 An invalid pointer dereference flaw was found in the Wireshark SMB and SMB2 dissectors. If Wireshark read a malformed packet off a network or opened a malicious dump file, it could crash or, possibly, execute arbitrary code as the user running Wireshark. (CVE-2009-4377) Several buffer overflow flaws were found in the Wireshark LWRES dissector. If Wireshark read a malformed packet off a network or opened a malicious dump file, it could crash or, possibly, execute arbitrary code as the user running Wireshark. (CVE-2010-0304) Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file. (CVE-2009-2560, CVE-2009-2562, CVE-2009-2563, CVE-2009-3550, CVE-2009-3829) All running instances of Wireshark must be restarted for the update to take effect. Note: libsmi was added to SL4 and SL5 because it was a new dependency for wireshark and older versions of SL4 and SL5 did not have libsmi. SL 3.0.x SRPMS: wireshark-1.0.11-EL3.6.src.rpm i386: wireshark-1.0.11-EL3.6.i386.rpm wireshark-gnome-1.0.11-EL3.6.i386.rpm x86_64: wireshark-1.0.11-EL3.6.x86_64.rpm wireshark-gnome-1.0.11-EL3.6.x86_64.rpm SL 4.x SRPMS: wireshark-1.0.11-1.el4_8.5.src.rpm i386: libsmi-0.4.5-5.el4.i386.rpm libsmi-devel-0.4.5-5.el4.i386.rpm wireshark-1.0.11-1.el4_8.5.i386.rpm wireshark-gnome-1.0.11-1.el4_8.5.i386.rpm x86_64: libsmi-0.4.5-5.el4.x86_64.rpm libsmi-devel-0.4.5-5.el4.x86_64.rpm wireshark-1.0.11-1.el4_8.5.x86_64.rpm wireshark-gnome-1.0.11-1.el4_8.5.x86_64.rpm SL 5.x SRPMS: wireshark-1.0.11-1.el5_5.5.src.rpm i386: libsmi-0.4.5-2.el5.i386.rpm libsmi-devel-0.4.5-2.el5.i386.rpm wireshark-1.0.11-1.el5_5.5.i386.rpm wireshark-gnome-1.0.11-1.el5_5.5.i386.rpm x86_64: libsmi-0.4.5-2.el5.i386.rpm libsmi-0.4.5-2.el5.x86_64.rpm libsmi-devel-0.4.5-2.el5.i386.rpm libsmi-devel-0.4.5-2.el5.x86_64.rpm wireshark-1.0.11-1.el5_5.5.x86_64.rpm wireshark-gnome-1.0.11-1.el5_5.5.x86_64.rpm -Connie Sieh -Troy Dawson