<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>183520</bug_id>
          
          <creation_ts>2007-06-28 13:21 0000</creation_ts>
          <short_desc>net-analyzer/wireshark &lt; 0.99.6 multiple vulnerabilities (CVE-2007-3389, 3390, 3391, 3392, 3393)</short_desc>
          <delta_ts>2007-08-16 22:06:11 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.wireshark.org/docs/relnotes/wireshark-0.99.6.html</bug_file_loc>
          <status_whiteboard>B? [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>chainsaw@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>carlo@gentoo.org</cc>
    
    <cc>netmon@gentoo.org</cc>
    
    <cc>ssuominen@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>chainsaw@gentoo.org</who>
            <bug_when>2007-06-28 13:21:13 0000</bug_when>
            <thetext>#

Wireshark could crash when dissecting an HTTP chunked response. (Bug 1394)

Versions affected: 0.99.5

#

On some systems, Wireshark could crash while reading iSeries capture files. (Bug 1415)

Versions affected: 0.10.14 to 0.99.5

#

Wireshark could exhaust system memory while reading a malformed DCP ETSI packet. (Bug 1264)

Versions affected: 0.99.5

#

Wireshark could loop excessively while reading a malformed SSL packet. (Bug 1582)

Versions affected: ?

#

The DHCP/BOOTP dissector was susceptible to an off-by-one error. (Bug 1416)

Versions affected: ?

#

Wireshark could loop excessively while reading a malformed MMS packet. (Bug 1382)

Versions affected: ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-06-28 13:36:32 0000</bug_when>
            <thetext>*** Bug 183521 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-06-28 14:45:03 0000</bug_when>
            <thetext>no reason to restrict this bug</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-06-29 21:11:36 0000</bug_when>
            <thetext>netmon please advise and patch as necessary.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jokey@gentoo.org</who>
            <bug_when>2007-07-06 16:11:39 0000</bug_when>
            <thetext>Bumped in CVS though I&apos;d be happy for another pair of eyes first if all security issues are really fixed...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 07:46:36 0000</bug_when>
            <thetext>Seems like mostly minor issues. Anyways.

Arches please test and mark stable. Target keywords are:

wireshark-0.99.6.ebuild:KEYWORDS=&quot;alpha amd64 hppa ia64 ppc ppc64 sparc x86 ~x86-fbsd&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-07-15 16:48:58 0000</bug_when>
            <thetext>pva has the patch for the --as-needed failure...so we could wait until he adds it...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-15 18:08:06 0000</bug_when>
            <thetext>Back to ebuild awaiting patch.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ssuominen@gentoo.org</who>
            <bug_when>2007-07-15 20:27:38 0000</bug_when>
            <thetext>(In reply to comment #7)
&gt; Back to ebuild awaiting patch.
&gt; 

I&apos;ve just fixed the issue with asneeded so it should be ok to proceed.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-07-16 15:34:12 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-07-16 16:45:19 0000</bug_when>
            <thetext>alpha/ia64/x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>cryos@gentoo.org</who>
            <bug_when>2007-07-16 18:57:01 0000</bug_when>
            <thetext>Stable on amd64.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-07-16 18:59:05 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-07-16 22:38:31 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-07-20 18:31:40 0000</bug_when>
            <thetext>ppc stable - time for glsa voting</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-07-20 20:57:29 0000</bug_when>
            <thetext>although it&apos;s mainly minor issues like Jaervosz pointed out, there&apos;s still the off-by-one error, which means possible remote code execution, so I vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-07-22 07:33:26 0000</bug_when>
            <thetext>I tend to vote YES.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>aetius@gentoo.org</who>
            <bug_when>2007-07-24 10:55:44 0000</bug_when>
            <thetext>Two yes votes = glsa request.

CVE-2007-3389
CVE-2007-3390
CVE-2007-3391
CVE-2007-3392
CVE-2007-3393

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-08-16 22:06:11 0000</bug_when>
            <thetext>GLSA 200708-12!</thetext>
          </long_desc>
      
    </bug>

</bugzilla>