Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66454
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1942-1)
Summary:The remote host is missing an update for the Debian 'wireshark' package(s) announced via the DSA-1942-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'wireshark' package(s) announced via the DSA-1942-1 advisory.

Vulnerability Insight:
Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2009-2560

A NULL pointer dereference was found in the RADIUS dissector.

CVE-2009-3550

A NULL pointer dereference was found in the DCERP/NT dissector.

CVE-2009-3829

An integer overflow was discovered in the ERF parser.

This update also includes fixes for three minor issues (CVE-2008-1829, CVE-2009-2562, CVE-2009-3241), which were scheduled for the next stable point update. Also CVE-2009-1268 was fixed for Etch. Since this security update was issued prior to the release of the point update, the fixes were included.

For the old stable distribution (etch), this problem has been fixed in version 0.99.4-5.etch.4.

For the stable distribution (lenny), this problem has been fixed in version 1.0.2-3+lenny7.

For the unstable distribution (sid) these problems have been fixed in version 1.2.3-1.

We recommend that you upgrade your Wireshark packages.

Affected Software/OS:
'wireshark' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1829
BugTraq ID: 35081
http://www.securityfocus.com/bid/35081
Debian Security Information: DSA-1942 (Google Search)
http://www.debian.org/security/2009/dsa-1942
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html
http://www.mandriva.com/security/advisories?name=MDVSA-2009:125
http://osvdb.org/54629
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9270
http://www.redhat.com/support/errata/RHSA-2009-1100.html
http://www.securitytracker.com/id?1022274
http://secunia.com/advisories/35201
http://secunia.com/advisories/35224
http://secunia.com/advisories/35248
http://secunia.com/advisories/35464
http://secunia.com/advisories/37477
http://www.vupen.com/english/advisories/2009/1408
XForce ISS Database: wireshark-pcnfsd-dos(50686)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50686
Common Vulnerability Exposure (CVE) ID: CVE-2009-2560
BugTraq ID: 35748
http://www.securityfocus.com/bid/35748
BugTraq ID: 36846
http://www.securityfocus.com/bid/36846
http://www.mandriva.com/security/advisories?name=MDVSA-2009:194
http://www.openwall.com/lists/oss-security/2009/07/22/2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10403
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6416
http://secunia.com/advisories/35884
http://secunia.com/advisories/37175
http://secunia.com/advisories/37409
http://www.vupen.com/english/advisories/2009/1970
http://www.vupen.com/english/advisories/2009/3061
XForce ISS Database: wireshark-radius-dissector-dos(54019)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54019
Common Vulnerability Exposure (CVE) ID: CVE-2009-2562
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564
http://www.openwall.com/lists/oss-security/2009/09/18/2
http://www.openwall.com/lists/oss-security/2009/09/17/15
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11643
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5625
Common Vulnerability Exposure (CVE) ID: CVE-2009-3241
BugTraq ID: 36408
http://www.securityfocus.com/bid/36408
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3986
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6162
http://secunia.com/advisories/36754
SuSE Security Announcement: SUSE-SR:2009:016 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html
Common Vulnerability Exposure (CVE) ID: CVE-2009-3550
36846
37175
37409
37477
ADV-2009-3061
DSA-1942
http://www.wireshark.org/docs/relnotes/wireshark-1.0.10.html
http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.html
http://www.wireshark.org/security/wnpa-sec-2009-07.html
http://www.wireshark.org/security/wnpa-sec-2009-08.html
oval:org.mitre.oval:def:10103
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10103
oval:org.mitre.oval:def:6005
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6005
wireshark-dcerpcnt-dos(54017)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54017
Common Vulnerability Exposure (CVE) ID: CVE-2009-3829
CERT/CC vulnerability note: VU#676492
http://www.kb.cert.org/vuls/id/676492
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5979
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9945
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.