Wireshark LDAP/CPHAP/Tektronix Bugs Let Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1022027 |
|
SecurityTracker URL: http://securitytracker.com/id/1022027
|
|
CVE Reference:
CVE-2009-1267, CVE-2009-1268, CVE-2009-1269
(Links to External Site)
|
Date: Apr 10 2009
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 0.99.2 to 1.0.6
|
Description:
Several vulnerabilities were reported in Wireshark. A remote user can cause denial of service conditions.
A remote user can send specially crafted data to cause the target service to crash.
The LDAP dissector is affected on Windows-based systems [CVE-2009-1267]. Versions 0.99.2 to 1.0.6 are affected.
The Check Point High-Availability Protocol (CPHAP) dissector is affected in versions 0.99.6 to 1.0.6 [CVE-2009-1268].
A Tektronix .rf5 file can trigger a crash in versions 0.99.6 to 1.0.6 [CVE-2009-1269].
|
Impact:
A remote user can cause Wireshark to crash.
|
Solution:
The vendor has issued a fix (1.0.7).
The vendor's advisory is available at:
http://www.wireshark.org/security/wnpa-sec-2009-02.html
|
Vendor URL: www.wireshark.org/security/wnpa-sec-2009-02.html (Links to External Site)
|
Cause:
Input validation error, State error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Thu, 9 Apr 2009 23:59:53 -0400
Subject: Wireshark
|
http://www.wireshark.org/security/wnpa-sec-2009-02.html
Wireshark 1.0.7 fixes the following vulnerabilities:
* The PROFINET dissector was vulnerable to a format string overflow. (Bug 3382) Versions affected: 0.99.6 to 1.0.6 CVE-2009-1210
* The LDAP dissector could crash on Windows. (Bug 3262) Versions affected: 0.99.2 to 1.0.6 CVE-2009-1267
* The Check Point High-Availability Protocol (CPHAP) dissector could crash. (Bug 3269) Versions affected: 0.9.6 to 1.0.6 CVE-2009-1268
* Wireshark could crash while loading a Tektronix .rf5 file. (Bug 3366) Versions affected: 0.99.6 to 1.0.6 CVE-2009-1269
|
|