Описание
ELSA-2010-0625: wireshark security update (MODERATE)
[1.0.15-1.0.1.el5_5.1]
- Add oracle-ocfs2-network.patch
[1.0.15-1]
- upgrade to 1.0.15
- http://www.wireshark.org/docs/relnotes/wireshark-1.0.15.html
- fixes CVE-2010-2287 CVE-2010-2284
- Related: #612239
[1.0.14-1.2]
- fix corner case in CVE-2010-2284
- Related: #612239
[1.0.14-1]
- upgrade to 1.0.14
- http://www.wireshark.org/docs/relnotes/wireshark-1.0.14.html
- fixes CVE-2010-1455 CVE-2010-2283 CVE-2010-2284 CVE-2010-2286 CVE-2010-2287
- Resolves: #612239
Обновленные пакеты
Oracle Linux 5
Oracle Linux ia64
wireshark
1.0.15-1.0.1.el5_5.1
wireshark-gnome
1.0.15-1.0.1.el5_5.1
Oracle Linux x86_64
wireshark
1.0.15-1.0.1.el5_5.1
wireshark-gnome
1.0.15-1.0.1.el5_5.1
Oracle Linux i386
wireshark
1.0.15-1.0.1.el5_5.1
wireshark-gnome
1.0.15-1.0.1.el5_5.1
Ссылки на источники
Связанные уязвимости
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark ...
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.