| From: |
| updates@fedoraproject.org |
| To: |
| package-announce@lists.fedoraproject.org |
| Subject: |
| [SECURITY] Fedora 13 Update: wireshark-1.2.10-1.fc13 |
| Date: |
| Thu, 02 Sep 2010 20:45:30 +0000 |
| Message-ID: |
| <20100902204530.C0E72110A4E@bastion02.phx2.fedoraproject.org> |
| Archive-link: |
| Article, Thread
|
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-13416
2010-08-24 20:36:29
--------------------------------------------------------------------------------
Name : wireshark
Product : Fedora 13
Version : 1.2.10
Release : 1.fc13
URL : http://www.wireshark.org/
Summary : Network traffic analyzer
Description :
Wireshark is a network traffic analyzer for Unix-ish operating systems.
This package lays base for libpcap, a packet capture and filtering
library, contains command-line utilities, contains plugins and
documentation for wireshark. A graphical user interface is packaged
separately to GTK+ package.
--------------------------------------------------------------------------------
Update Information:
Update to upstream version 1.2.10: *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.9.html *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html fixing multiple
security issues: * http://www.wireshark.org/security/wnpa-sec-2010-06.html *
http://www.wireshark.org/security/wnpa-sec-2010-08.html
--------------------------------------------------------------------------------
ChangeLog:
* Tue Aug 24 2010 Jan Safranek <jsafrane@redhat.com> - 1.2.10-1
- upgrade to 1.2.10
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html
- Resolves: #625940 CVE-2010-2287 CVE-2010-2286 CVE-2010-2284 CVE-2010-2283
* Mon May 17 2010 Radek Vokal <rvokal@redhat.com> - 1.2.8-3
- removing traling bracket from python_sitearch (#592391)
* Fri May 7 2010 Radek Vokal <rvokal@redhat.com> - 1.2.8-2
- add libtool patch
* Fri May 7 2010 Radek Vokal <rvokal@redhat.com> - 1.2.8-1
- use sitearch instead of sitelib to avoid pyo and pyc conflicts
- upgrade to 1.2.8
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.8.html
- rebuild with GeoIP support (needs to be turned on in IP protocol preferences)
- bring back -pie
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #604308 - CVE-2010-2287 CVE-2010-2995 wireshark: SigComp UDVM dissector buffer
overruns
https://bugzilla.redhat.com/show_bug.cgi?id=604308
[ 2 ] Bug #604302 - CVE-2010-2286 wireshark: SigComp UDVM dissector infinite loop
https://bugzilla.redhat.com/show_bug.cgi?id=604302
[ 3 ] Bug #604292 - CVE-2010-2284 wireshark: ASN.1 BER dissector stack overrun
https://bugzilla.redhat.com/show_bug.cgi?id=604292
[ 4 ] Bug #604290 - CVE-2010-2283 wireshark: SMB dissector NULL pointer dereference
https://bugzilla.redhat.com/show_bug.cgi?id=604290
[ 5 ] Bug #623843 - CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple
vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=623843
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update wireshark' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-...
(
Log in to post comments)