|
|
Log in / Subscribe / Register

Pardus alert 2011-57 (wireshark)

From:  Meltem Parmaksız <meltem@pardus.org.tr>
To:  pardus-security@pardus.org.tr
Subject:  [Pardus-security] [PLSA 2011-57] Wireshark: Multiple Vulnerabilities
Date:  Mon, 21 Mar 2011 09:23:38 +0200
Message-ID:  <201103210923.38738.meltem@pardus.org.tr>

------------------------------------------------------------------------ Pardus Linux Security Advisory 2011-57 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2011-03-21 Severity: 3 Type: Remote ------------------------------------------------------------------------ Summary ======= Multiple vulnerabilities have been fixed in wireshark. Description =========== CVE-2011-1138: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet. CVE-2011-1139: wiretap/pcapng.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) via a pcap-ng file that contains a large packet-length field. CVE-2011-1140: Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet. CVE-2011-1141: epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements. CVE-2011-1142: Stack consumption vulnerability in the dissect_ber_choice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 might allow remote attackers to cause a denial of service (infinite loop) via vectors involving self-referential ASN.1 CHOICE values. Affected packages: Pardus 2009: wireshark, all before 1.4.4-42-19 Resolution ========== There are update(s) for wireshark. You can update them via Package Manager or with a single command from console: pisi up wireshark References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=17271 * http://bugs.pardus.org.tr/show_bug.cgi?id=17275 * http://bugs.pardus.org.tr/show_bug.cgi?id=17279 * http://bugs.pardus.org.tr/show_bug.cgi?id=17283 * http://bugs.pardus.org.tr/show_bug.cgi?id=17287 ------------------------------------------------------------------------ _______________________________________________ Pardus-Security mailing list Pardus-Security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds