Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.60052
Category:FreeBSD Local Security Checks
Title:wireshark -- multiple vulnerabilities
Summary:The remote host is missing an update to the system; as announced in the referenced advisory.
Description:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following packages are affected:

wireshark
wireshark-lite
ethereal
ethereal-lite
tethereal
tethereal-lite

CVE-2007-6438
Unspecified vulnerability in the SMB dissector in Wireshark (formerly
Ethereal) 0.99.6 allows remote attackers to cause a denial of service
via unknown vectors. NOTE: this identifier originally included MP3
and NCP, but those issues are already covered by CVE-2007-6111.

CVE-2007-6439
Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause
a denial of service (infinite or large loop) via the (1) IPv6 or (2)
USB dissector, which can trigger resource consumption or a crash.
NOTE: this identifier originally included Firebird/Interbase, but it
is already covered by CVE-2007-6116. The DCP ETSI issue is already
covered by CVE-2007-6119.

CVE-2007-6441
The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows
remote attackers to cause a denial of service (crash) via unknown
vectors related to 'unaligned access on some platforms.'

CVE-2007-6450
The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6
allows remote attackers to cause a denial of service (infinite loop)
via unknown vectors.

CVE-2007-6451
Unspecified vulnerability in the CIP dissector in Wireshark (formerly
Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial
of service (crash) via unknown vectors that trigger allocation of
large amounts of memory.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-6112
1018988
http://securitytracker.com/id?1018988
20080103 rPSA-2008-0004-1 tshark wireshark
http://www.securityfocus.com/archive/1/485792/100/0/threaded
26532
http://www.securityfocus.com/bid/26532
27777
http://secunia.com/advisories/27777
28197
http://secunia.com/advisories/28197
28207
http://secunia.com/advisories/28207
28288
http://secunia.com/advisories/28288
28304
http://secunia.com/advisories/28304
28325
http://secunia.com/advisories/28325
28564
http://secunia.com/advisories/28564
29048
http://secunia.com/advisories/29048
ADV-2007-3956
http://www.vupen.com/english/advisories/2007/3956
FEDORA-2007-4590
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00606.html
FEDORA-2007-4690
https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00712.html
GLSA-200712-23
http://security.gentoo.org/glsa/glsa-200712-23.xml
MDVSA-2008:001
http://www.mandriva.com/security/advisories?name=MDVSA-2008:001
MDVSA-2008:1
http://www.mandriva.com/security/advisories?name=MDVSA-2008:1
RHSA-2008:0058
http://www.redhat.com/support/errata/RHSA-2008-0058.html
SUSE-SR:2008:004
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00008.html
http://bugs.gentoo.org/show_bug.cgi?id=199958
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0004
http://www.wireshark.org/security/wnpa-sec-2007-03.html
https://issues.rpath.com/browse/RPL-1975
oval:org.mitre.oval:def:14561
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14561
oval:org.mitre.oval:def:9772
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9772
Common Vulnerability Exposure (CVE) ID: CVE-2007-6113
1018635
http://www.securitytracker.com/id?1018635
20070904 Wireshark DNP3 Dissector Infinite Loop Vulnerability
http://www.securityfocus.com/archive/1/478497/100/0/threaded
28583
http://secunia.com/advisories/28583
3095
http://securityreason.com/securityalert/3095
4347
https://www.exploit-db.com/exploits/4347
RHSA-2008:0059
http://www.redhat.com/support/errata/RHSA-2008-0059.html
http://www.securiteam.com/securitynews/5LP0V00MAI.html
oval:org.mitre.oval:def:9841
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9841
wireshark-dnp3-dos(36392)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36392
Common Vulnerability Exposure (CVE) ID: CVE-2007-6114
27817
http://secunia.com/advisories/27817
DSA-1414
http://www.debian.org/security/2007/dsa-1414
oval:org.mitre.oval:def:10708
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10708
Common Vulnerability Exposure (CVE) ID: CVE-2007-6115
oval:org.mitre.oval:def:14578
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14578
oval:org.mitre.oval:def:9726
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9726
Common Vulnerability Exposure (CVE) ID: CVE-2007-6117
http://www.wireshark.org/docs/relnotes/wireshark-0.99.7.html
https://bugzilla.redhat.com/show_bug.cgi?id=397331
oval:org.mitre.oval:def:11508
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11508
Common Vulnerability Exposure (CVE) ID: CVE-2007-6118
oval:org.mitre.oval:def:10659
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10659
Common Vulnerability Exposure (CVE) ID: CVE-2007-6120
oval:org.mitre.oval:def:14802
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14802
oval:org.mitre.oval:def:9488
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9488
Common Vulnerability Exposure (CVE) ID: CVE-2007-6121
oval:org.mitre.oval:def:11374
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11374
Common Vulnerability Exposure (CVE) ID: CVE-2007-6438
27071
http://www.securityfocus.com/bid/27071
oval:org.mitre.oval:def:11785
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11785
oval:org.mitre.oval:def:14734
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14734
wireshark-smb-dissector-dos(39178)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39178
Common Vulnerability Exposure (CVE) ID: CVE-2007-6439
oval:org.mitre.oval:def:10331
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10331
oval:org.mitre.oval:def:15002
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15002
wireshark-ipv6-dissector-dos(39180)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39180
wireshark-usb-dissector-dos(39181)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39181
Common Vulnerability Exposure (CVE) ID: CVE-2007-6441
oval:org.mitre.oval:def:10452
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10452
oval:org.mitre.oval:def:14126
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14126
wireshark-wimax-dissector-dos(39183)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39183
Common Vulnerability Exposure (CVE) ID: CVE-2007-6450
28315
http://secunia.com/advisories/28315
DSA-1446
http://www.debian.org/security/2008/dsa-1446
oval:org.mitre.oval:def:11442
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11442
wireshark-rpl-dissector-dos(39186)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39186
Common Vulnerability Exposure (CVE) ID: CVE-2007-6451
oval:org.mitre.oval:def:9685
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9685
wireshark-cip-dissector-dos(39187)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39187
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.