LWN.net Logo

wireshark: arbitrary code execution

Package(s):wireshark CVE #(s):CVE-2010-2995
Created:August 12, 2010 Updated:April 19, 2011
Description:

From the Red Hat advisory:

Multiple buffer overflow flaws were found in the Wireshark SigComp Universal Decompressor Virtual Machine (UDVM) dissector. If Wireshark read a malformed packet off a network or opened a malicious dump file, it could crash or, possibly, execute arbitrary code as the user running Wireshark. (CVE-2010-2287, CVE-2010-2995)

Alerts:
Gentoo 201110-02 2011-10-09
SUSE SUSE-SR:2011:007 2011-04-19
openSUSE openSUSE-SU-2011:0010-2 2011-01-12
SUSE SUSE-SR:2011:001 2011-01-11
SUSE SUSE-SR:2011:002 2011-01-25
openSUSE openSUSE-SU-2011:0010-1 2011-01-04
Fedora FEDORA-2010-13427 2010-08-24
Fedora FEDORA-2010-13416 2010-08-24
Debian DSA-2101-1 2010-08-31
CentOS CESA-2010:0625 2010-08-27
CentOS CESA-2010:0625 2010-08-23
Red Hat RHSA-2010:0625-01 2010-08-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds