Friday, December 3, 2010

Wireshark: Moderate security update

Amplify’d from www.criticalwatch.com
RHSA-2010:0924-01: [RHSA-2010:0924-01] Moderate: wireshark security update
Product: Red Hat Enterprise Linux
Description:



Wireshark is a program for monitoring network traffic. Wireshark was

previously known as Ethereal.



A heap-based buffer overflow flaw was found in the Wireshark Local Download

Sharing Service (LDSS) dissector. If Wireshark read a malformed packet off

a network or opened a malicious dump file, it could crash or, possibly,

execute arbitrary code as the user running Wireshark. (CVE-2010-4300)



A denial of service flaw was found in Wireshark. Wireshark could crash or

stop responding if it read a malformed packet off a network, or opened a

malicious dump file. (CVE-2010-3445)



Users of Wireshark should upgrade to these updated packages, which contain

Wireshark version 1.2.13, and resolve these issues. All running instances

of Wireshark must be restarted for the update to take effect.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment