LWN.net Logo

wireshark: multiple vulnerabilities

Package(s):wireshark CVE #(s):CVE-2009-0599 CVE-2009-0600 CVE-2009-0601
Created:February 27, 2009 Updated:June 30, 2009
Description: From the Mandriva advisory:

Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file. (CVE-2009-0599)

Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame. (CVE-2009-0600)

Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable. (CVE-2009-0601)

Wireshark 1.0.6 is not vulnerable to these issues.

Alerts:
Gentoo 200906-05 2009-06-30
Fedora FEDORA-2009-1877 2009-02-19
rPath rPSA-2009-0040-1 2009-03-12
CentOS CESA-2009:0313 2009-03-05
Red Hat RHSA-2009:0313-01 2009-03-04
Fedora FEDORA-2009-1798 2009-02-17
SuSE SUSE-SR:2009:005 2009-03-02
Mandriva MDVSA-2009:058 2008-02-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds