Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
BID:37407
Info
Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
| Bugtraq ID: | 37407 |
| Class: | Unknown |
| CVE: |
CVE-2009-4376 CVE-2009-4377 CVE-2009-4378 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2009 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | Wireshark |
| Vulnerable: |
Wireshark Wireshark 1.2.4 Wireshark Wireshark 1.2.3 Wireshark Wireshark 1.2.2 Wireshark Wireshark 1.2.1 Wireshark Wireshark 1.2 Wireshark Wireshark 1.0.10 Wireshark Wireshark 1.0.9 Wireshark Wireshark 1.0.8 Wireshark Wireshark 1.0.7 Wireshark Wireshark 1.0.6 Wireshark Wireshark 1.0.5 Wireshark Wireshark 1.0.4 Wireshark Wireshark 1.0.3 Wireshark Wireshark 1.0.2 Wireshark Wireshark 1.0.1 Wireshark Wireshark 1.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise 11 SuSE SUSE Linux Enterprise 10 SP3 SuSE SUSE Linux Enterprise 10 SP2 S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 3.0 Pardus Linux 2009 0 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Ethereal Group Ethereal 0.99 Ethereal Group Ethereal 0.10.14 Ethereal Group Ethereal 0.10.13 Ethereal Group Ethereal 0.10.12 Ethereal Group Ethereal 0.10.11 Ethereal Group Ethereal 0.10.10 Ethereal Group Ethereal 0.10.9 Ethereal Group Ethereal 0.10.8 Ethereal Group Ethereal 0.10.7 Ethereal Group Ethereal 0.10.6 Ethereal Group Ethereal 0.10.5 Ethereal Group Ethereal 0.10.4 Ethereal Group Ethereal 0.10.3 Ethereal Group Ethereal 0.10.2 Ethereal Group Ethereal 0.10.1 Ethereal Group Ethereal 0.10 .10 Ethereal Group Ethereal 0.10 Ethereal Group Ethereal 0.9.16 Ethereal Group Ethereal 0.9.15 Ethereal Group Ethereal 0.9.14 Ethereal Group Ethereal 0.9.13 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 5.1 Avaya Messaging Storage Server 5.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 SP1 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Aura System Platform 1.0 Avaya Aura SIP Enablement Services 5.2.1 Avaya Aura SIP Enablement Services 3.1.1 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura SIP Enablement Services 3.0 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Communication Manager 4.0 Avaya Aura Communication Manager 4.0 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
Wireshark Wireshark 1.2.5 Avaya Aura SIP Enablement Services 5.2.1 SSP#1 |
Discussion
Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities and a buffer-overflow vulnerability.
Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.
These issues affect Wireshark 0.9.0 through 1.2.4.
Wireshark is prone to multiple denial-of-service vulnerabilities and a buffer-overflow vulnerability.
Exploiting these issues may allow attackers to crash the application and deny service to legitimate users. Attackers may also execute arbitrary code in the context of vulnerable users running the application.
These issues affect Wireshark 0.9.0 through 1.2.4.
Exploit / POC
Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
Proof-of-concept capture files for the denial-of-service issues are available from the following locations:
https://bugs.wireshark.org/bugzilla/attachment.cgi?id=4055
http://www.wireshark.org/download/automated/captures/fuzz-2009-12-07-11141.pcap
Note that Symantec has not verified or tested these files.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Proof-of-concept capture files for the denial-of-service issues are available from the following locations:
https://bugs.wireshark.org/bugzilla/attachment.cgi?id=4055
http://www.wireshark.org/download/automated/captures/fuzz-2009-12-07-11141.pcap
Note that Symantec has not verified or tested these files.
Currently we are not aware of any working exploits for the buffer-overflow issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.0 x86_64
Mandriva Linux Mandrake 2008.0
Mandriva Linux Mandrake 2010.0
Mandriva Linux Mandrake 2009.1
Mandriva Linux Mandrake 2009.1 x86_64
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2010.0 x86_64
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva dumpcap-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark-devel-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark0-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2008.0
-
Mandriva dumpcap-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark-devel-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark0-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva dumpcap-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark-devel-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark0-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.2.5-0.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1
-
Mandriva dumpcap-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark-devel-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark0-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva dumpcap-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark-devel-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark0-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva dumpcap-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark-devel-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark0-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdvmes5.x86_64.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva dumpcap-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark-devel-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwireshark0-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.0.11-0.1mdvmes5.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva dumpcap-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark-devel-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64wireshark0-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva rawshark-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva tshark-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva wireshark-tools-1.2.5-0.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
References
Wireshark 0.9.0 through 1.2.4 Multiple Vulnerabilities
References:
References:
- Wireshark Homepage (Wireshark)
- ASA-2010-116 wireshark security update (RHSA-2010-0360) (Avaya)
- Multiple vulnerabilities in Wireshark version 0.9.0 to 1.2.4 (Wireshark)
- Wireshark Bug Database �?? Bug 4294 (Wireshark)
- Wireshark Bug Database �?? Bug 4301 (Wireshark)
- Wireshark Bug Database �?? Bug 4319 (Wireshark)
- wnpa-sec-2010-01 (Wireshark)