Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 297388 (CVE-2009-4376) - <net-analyzer/wireshark-1.2.5: Multiple vulnerabilities (CVE-2009-{4376,4377,4378})
Summary: <net-analyzer/wireshark-1.2.5: Multiple vulnerabilities (CVE-2009-{4376,4377,...
Status: RESOLVED FIXED
Alias: CVE-2009-4376
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.wireshark.org/security/wnp...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-12-18 06:22 UTC by Peter Volkov (RETIRED)
Modified: 2010-06-02 21:28 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter Volkov (RETIRED) gentoo-dev 2009-12-18 06:22:07 UTC
http://www.wireshark.org/security/wnpa-sec-2009-09.html
Wireshark 1.2.5 fixes the following vulnerabilities:

    * The Daintree SNA file parser could overflow a buffer. (https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4294)
      Versions affected: 1.2.0 to 1.2.4
    * The SMB and SMB2 dissectors could crash. (https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4301)
      Versions affected: 0.9.0 to 1.2.4
    * The IPMI dissector could crash on Windows. (https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4319)
      Versions affected: 1.2.0 to 1.2.4
Comment 1 Peter Volkov (RETIRED) gentoo-dev 2009-12-18 06:23:42 UTC
New version is in the tree. Arch teams, please, stabilize.
Comment 2 Christian Faulhammer (RETIRED) gentoo-dev 2009-12-18 09:51:11 UTC
x86 stable
Comment 3 Richard Freeman gentoo-dev 2009-12-19 01:43:50 UTC
amd64 stable
Comment 4 Jeroen Roovers (RETIRED) gentoo-dev 2009-12-19 16:14:20 UTC
Stable for HPPA.
Comment 5 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-12-20 08:55:11 UTC
I'm not sure on the implications here. The buffer overflow was caused by a non-constrained %s in scanf. Upstream quotes a crash, but as seen with other issues (htmldoc) code execution might be possible. Setting B2? for the time being.
Comment 6 Brent Baude (RETIRED) gentoo-dev 2009-12-20 16:14:33 UTC
ppc64 done
Comment 7 Raúl Porcel (RETIRED) gentoo-dev 2009-12-21 14:31:46 UTC
alpha/ia64/sparc stable
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2009-12-22 15:40:23 UTC
Stable for PPC.
Comment 9 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-01-08 17:25:37 UTC
CVE confirms code execution. Rating B2, scheduled for a GLSA.
Comment 10 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-01-08 17:45:31 UTC
CVE-2009-4376 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4376):
  Buffer overflow in the daintree_sna_read function in the Daintree SNA
  file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers
  to cause a denial of service (crash) and possibly execute arbitrary
  code via a crafted packet.

CVE-2009-4377 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4377):
  The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4
  allow remote attackers to cause a denial of service (crash) via a
  crafted packet, as demonstrated by fuzz-2009-12-07-11141.pcap.

CVE-2009-4378 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4378):
  The IPMI dissector in Wireshark 1.2.0 through 1.2.4, when running on
  Windows, allows remote attackers to cause a denial of service (crash)
  via a crafted packet, related to "formatting a date/time using
  strftime."

Comment 11 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-06-02 21:28:07 UTC
GLSA 201006-05