SCIENTIFIC-LINUX-ERRATA Archives

November 2007

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Tue, 13 Nov 2007 16:53:27 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (25 lines)
Synopsis:	Low: wireshark security update
Issue date:	2007-11-07
CVE Names:	CVE-2007-3389 CVE-2007-3390 CVE-2007-3391
                 CVE-2007-3392 CVE-2007-3393

Several denial of service bugs were found in Wireshark's HTTP, iSeries, 
DCP ETSI, SSL, MMS, DHCP and BOOTP protocol dissectors.  It was possible 
for Wireshark to crash or stop responding if it read a malformed packet 
off the network. (CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, 
CVE-2007-3392, CVE-2007-3393)

SL 5.x

   SRPMS:
wireshark-0.99.6-1.el5.src.rpm
   i386:
wireshark-0.99.6-1.el5.i386.rpm
wireshark-gnome-0.99.6-1.el5.i386.rpm
   x86_64:
wireshark-0.99.6-1.el5.x86_64.rpm
wireshark-gnome-0.99.6-1.el5.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2