Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 236515 (CVE-2008-3146) - net-analyzer/wireshark <1.0.3 NCP dissector DoS (CVE-2008-{3146,3932,3933,3934}))
Summary: net-analyzer/wireshark <1.0.3 NCP dissector DoS (CVE-2008-{3146,3932,3933,393...
Status: RESOLVED FIXED
Alias: CVE-2008-3146
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.wireshark.org/security/wnp...
Whiteboard: B3 [glsa]
Keywords:
: 236978 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-09-02 22:33 UTC by Robert Buchholz (RETIRED)
Modified: 2008-09-25 21:18 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-09-02 22:33:12 UTC
CVE-2008-3146 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3146):
  Unspecified vulnerability in Wireshark and Ethereal on SUSE Linux allows
  attackers to cause a denial of service (application crash) or possibly
  execute arbitrary code via unknown vectors.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-09-02 22:34:15 UTC
I inquired upstream on a release date.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-09-03 08:33:53 UTC
replied: "It should be out in the next couple of days."
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-09-04 23:11:23 UTC
It's out. To quote:

Wireshark 1.0.3 fixes the following vulnerabilities:

    * The NCP dissector was susceptible to a number of problems, including buffer overflows and an infinite loop. (Bug 2675)
      Versions affected: 0.9.7 to 1.0.2
    * Wireshark could crash while uncompressing zlib-compressed packet data. (Bug 2649)
      Versions affected: 0.10.14 to 1.0.2
    * Wireshark could crash while reading a Tektronix .rf5 file.
      Versions affected: 0.99.6 to 1.0.2 
Comment 4 Carsten Lohrke (RETIRED) gentoo-dev 2008-09-07 15:07:04 UTC
*** Bug 236978 has been marked as a duplicate of this bug. ***
Comment 5 Peter Volkov (RETIRED) gentoo-dev 2008-09-10 06:04:58 UTC
wireshark-1.0.3 was added to the tree. Arch teams, please, stabilize.
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2008-09-10 08:03:51 UTC
Stable for HPPA.
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2008-09-10 10:54:25 UTC
alpha/ia64/sparc/x86 stable
Comment 8 Brent Baude (RETIRED) gentoo-dev 2008-09-10 13:19:03 UTC
ppc and ppc64 stable
Comment 9 Olivier Crete (RETIRED) gentoo-dev 2008-09-10 14:15:33 UTC
amd64 done.. all arches done... your turn to glsa (or not)
Comment 10 Robert Buchholz (RETIRED) gentoo-dev 2008-09-12 14:07:36 UTC
CVE-2008-3932 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3932):
  Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to
  cause a denial of service (hang) via a crafted NCP packet that
  triggers an infinite loop.

CVE-2008-3933 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3933):
  Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers
  to cause a denial of service (crash) via a packet with crafted
  zlib-compressed data that triggers an invalid read in the
  tvb_uncompress function.

CVE-2008-3934 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3934):
  Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6
  through 1.0.2 allows attackers to cause a denial of service (crash)
  via a crafted Tektronix .rf5 file.
Comment 11 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-09-18 21:56:28 UTC
We already sent GLSA for this kind of stuff so... voting yes.
Comment 12 Tobias Heinlein (RETIRED) gentoo-dev 2008-09-22 12:39:18 UTC
YES too, request filed.
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-09-25 21:18:41 UTC
GLSA 200809-17