Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 145005

Summary: net-analyzer/wireshark-0.99.2 vulnerabilities
Product: Gentoo Security Reporter: Bernd Marienfeldt <bernd>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: major CC: chainsaw
Priority: High    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard:
Package list:
Runtime testing required: ---

Description Bernd Marienfeldt 2006-08-24 12:57:19 UTC
http://www.wireshark.org/security/wnpa-sec-2006-02.html

Wireshark 0.99.3 fixes the following vulnerabilities:

* The SCSI dissector could crash. Versions affected: 0.99.2. CVE: CVE-2006-4330

* If Wireshark was compiled with ESP decryption support, the IPsec ESP preference parser was susceptible to off-by-one errors. Versions affected: 0.99.2. CVE: CVE-2006-4331

* The DHCP dissector (and possibly others) in the Windows version of Wireshark could trigger a bug in Glib and crash. Versions affected: 0.10.13 - 0.99.2. CVE: CVE-2006-4332

* If the SSCOP dissector has a port range configured and the SSCOP payload protocol is Q.2931, a malformed packet could make the Q.2931 dissector use up available memory. No port range is configured by default. Versions affected: 0.7.9 - 0.99.2. CVE: CVE-2006-4333
Comment 1 Carsten Lohrke (RETIRED) gentoo-dev 2006-08-24 13:28:11 UTC

*** This bug has been marked as a duplicate of 144946 ***