_______________________________________________________________________
Package : wireshark
Date : December 3, 2009
Affected: 2008.0
_______________________________________________________________________
Problem Description:
Vulnerabilities have been discovered and corrected in wireshark,
affecting DCERPC/NT dissector, which allows remote attackers to cause
a denial of service (NULL pointer dereference and application crash)
via a file that records a malformed packet trace (CVE-2009-3550); and
in wiretap/erf.c which allows remote attackers to execute arbitrary
code or cause a denial of service (application crash) via a crafted
erf file (CVE-2009-3829).
The wireshark package has been updated to fix these vulnerabilities.
Update:
Packages for 2008.0 are being provided due to extended support for
Corporate products.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-3550
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-3829
_______________________________________________________________________