Stefan Esser discovered a buffer overflow in the SSL dissector.
"Fabiodds" discovered a buffer overflow in the iSeries trace
dissector.
CVE-2007-6117
A programming error was discovered in the HTTP dissector, which may
lead to denial of service.
CVE-2007-6118
The MEGACO dissector could be tricked into ressource exhaustion.
CVE-2007-6120
The Bluetooth SDP dissector could be tricked into an endless loop.
CVE-2007-6121
The RPC portmap dissector could be tricked into dereferencing
a NULL pointer.
For the stable distribution (etch), these problems have been fixed
in version 0.99.4-5.etch.1. Updates packages for sparc will be provided
later.
For the old stable distribution (sarge), these problems have been
fixed in version 0.10.10-2sarge10. (In Sarge Wireshark used to be
called Ethereal). Updates packages for sparc and m68k will be provided
later.
We recommend that you upgrade your wireshark/ethereal packages.
Upgrade instructions
- --------...
Get the latest Linux and open source security news straight to your inbox.