LWN.net Logo

wireshark: multiple vulnerabilities

Package(s):wireshark CVE #(s):CVE-2012-4285 CVE-2012-4287 CVE-2012-4288 CVE-2012-4289 CVE-2012-4296 CVE-2012-4297 CVE-2012-4291 CVE-2012-4292 CVE-2012-4293 CVE-2012-4290
Created:August 16, 2012 Updated:December 26, 2012
Description:

From the Mandriva advisory:

Multiple vulnerabilities was found and corrected in Wireshark:

The DCP ETSI dissector could trigger a zero division (CVE-2012-4285).

The MongoDB dissector could go into a large loop (CVE-2012-4287).

The XTP dissector could go into an infinite loop (CVE-2012-4288).

The AFP dissector could go into a large loop (CVE-2012-4289).

The RTPS2 dissector could overflow a buffer (CVE-2012-4296).

The GSM RLC MAC dissector could overflow a buffer (CVE-2012-4297).

The CIP dissector could exhaust system memory (CVE-2012-4291).

The STUN dissector could crash (CVE-2012-4292).

The EtherCAT Mailbox dissector could abort (CVE-2012-4293).

The CTDB dissector could go into a large loop (CVE-2012-4290).

Alerts:
Mandriva MDVSA-2012:134 2012-08-16
Mandriva MDVSA-2012:135 2012-08-16
Mageia MGASA-2012-0226 2012-08-18
openSUSE openSUSE-SU-2012:1035-1 2012-08-24
Fedora FEDORA-2012-12091 2012-08-27
Fedora FEDORA-2012-12085 2012-08-27
openSUSE openSUSE-SU-2012:1067-1 2012-08-30
Debian DSA-2590-1 2012-12-26
Oracle ELSA-2013-0125 2013-01-12
Scientific Linux SL-wire-20130116 2013-01-16
Mandriva MDVSA-2013:055 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds