Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69264
Category:Fedora Local Security Checks
Title:Fedora Core 13 FEDORA-2011-2620 (wireshark)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to wireshark
announced via advisory FEDORA-2011-2620.

References:

[ 1 ] Bug #676232 - CVE-2011-0538 Wireshark: memory corruption when reading a malformed pcap file (upstream bug #5652)
https://bugzilla.redhat.com/show_bug.cgi?id=676232
[ 2 ] Bug #678198 - CVE-2011-0713 Wireshark: heap-based buffer overflow when reading malformed Nokia DCT3 phone signalling traces
https://bugzilla.redhat.com/show_bug.cgi?id=678198
[ 3 ] Bug #639486 - CVE-2010-3445 wireshark: stack overflow in BER dissector
https://bugzilla.redhat.com/show_bug.cgi?id=639486
[ 4 ] Bug #681760 - CVE-2011-1143 Wireshark: Null pointer dereference causing application crash when reading malformed pcap file
https://bugzilla.redhat.com/show_bug.cgi?id=681760
[ 5 ] Bug #681754 - CVE-2011-1140 Wireshark: Multiple stack consumption vulnerabilities caused DoS via crafted SMB or CLDAP packet
https://bugzilla.redhat.com/show_bug.cgi?id=681754
[ 6 ] Bug #681753 - CVE-2011-1138 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
https://bugzilla.redhat.com/show_bug.cgi?id=681753
[ 7 ] Bug #681748 - CVE-2011-1139 Wireshark: Denial Of Service (application crash) via a pcap-ng file that contains a large packet-length field
https://bugzilla.redhat.com/show_bug.cgi?id=681748
[ 8 ] Bug #681756 - CVE-2011-1141 Wireshark: Malformed LDAP filter string causes Denial of Service via excessive memory consumption
https://bugzilla.redhat.com/show_bug.cgi?id=681756

Solution: Apply the appropriate updates.

This update can be installed with the yum update program. Use
su -c 'yum update wireshark' at the command line.
For more information, refer to Managing Software with yum,
available at http://docs.fedoraproject.org/yum/.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-2620

Risk factor : Critical

CVSS Score:
8.3

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0538
1025148
http://www.securitytracker.com/id?1025148
43759
http://secunia.com/advisories/43759
43795
http://secunia.com/advisories/43795
43821
http://secunia.com/advisories/43821
46167
http://www.securityfocus.com/bid/46167
ADV-2011-0622
http://www.vupen.com/english/advisories/2011/0622
ADV-2011-0626
http://www.vupen.com/english/advisories/2011/0626
ADV-2011-0719
http://www.vupen.com/english/advisories/2011/0719
ADV-2011-0747
http://www.vupen.com/english/advisories/2011/0747
DSA-2201
http://www.debian.org/security/2011/dsa-2201
FEDORA-2011-2620
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055664.html
FEDORA-2011-2632
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055650.html
FEDORA-2011-2648
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055364.html
MDVSA-2011:044
http://www.mandriva.com/security/advisories?name=MDVSA-2011:044
RHSA-2011:0369
http://www.redhat.com/support/errata/RHSA-2011-0369.html
RHSA-2011:0370
http://www.redhat.com/support/errata/RHSA-2011-0370.html
VU#215900
http://www.kb.cert.org/vuls/id/215900
[oss-security] 20110204 Wireshark: Freeing uninitialized pointer
http://openwall.com/lists/oss-security/2011/02/04/1
http://www.wireshark.org/docs/relnotes/wireshark-1.2.15.html
http://www.wireshark.org/docs/relnotes/wireshark-1.4.4.html
http://www.wireshark.org/security/wnpa-sec-2011-03.html
http://www.wireshark.org/security/wnpa-sec-2011-04.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5652
https://bugzilla.redhat.com/show_bug.cgi?id=676232
oval:org.mitre.oval:def:14605
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14605
wireshark-pcap-code-execution(65182)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65182
Common Vulnerability Exposure (CVE) ID: CVE-2010-3445
20100913 Wireshark 1.4.0 Malformed SNMP V1 Packet Denial of Service
http://archives.neohapsis.com/archives/bugtraq/2010-09/0088.html
42392
http://secunia.com/advisories/42392
42411
http://secunia.com/advisories/42411
42877
http://secunia.com/advisories/42877
43068
http://secunia.com/advisories/43068
43197
http://www.securityfocus.com/bid/43197
ADV-2010-3067
http://www.vupen.com/english/advisories/2010/3067
ADV-2010-3093
http://www.vupen.com/english/advisories/2010/3093
ADV-2011-0076
http://www.vupen.com/english/advisories/2011/0076
ADV-2011-0212
http://www.vupen.com/english/advisories/2011/0212
ADV-2011-0404
http://www.vupen.com/english/advisories/2011/0404
DSA-2127
http://www.debian.org/security/2010/dsa-2127
MDVSA-2010:200
http://www.mandriva.com/security/advisories?name=MDVSA-2010:200
RHSA-2010:0924
http://www.redhat.com/support/errata/RHSA-2010-0924.html
SUSE-SR:2011:001
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.html
SUSE-SR:2011:002
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
[oss-security] 20101001 Re: CVE requests: Poppler, Quassel, Pyfribidi, Overkill, DocUtils, FireGPG, Wireshark
http://www.openwall.com/lists/oss-security/2010/10/01/10
[oss-security] 20101011 Re: CVE requests: Poppler, Quassel, Pyfribidi, Overkill, DocUtils, FireGPG, Wireshark
http://www.openwall.com/lists/oss-security/2010/10/12/1
http://blogs.sun.com/security/entry/resource_management_errors_vulnerability_in
http://www.wireshark.org/security/wnpa-sec-2010-12.html
http://xorl.wordpress.com/2010/10/15/cve-2010-3445-wireshark-asn-1-ber-stack-overflow/
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5230
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-3445
oval:org.mitre.oval:def:14607
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14607
Common Vulnerability Exposure (CVE) ID: CVE-2011-1143
BugTraq ID: 46796
http://www.securityfocus.com/bid/46796
CERT/CC vulnerability note: VU#215900
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16209
http://secunia.com/advisories/44169
http://secunia.com/advisories/48947
SuSE Security Announcement: openSUSE-SU-2011:0347 (Google Search)
https://hermes.opensuse.org/messages/8086844
Common Vulnerability Exposure (CVE) ID: CVE-2011-1140
Debian Security Information: DSA-2201 (Google Search)
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14715
Common Vulnerability Exposure (CVE) ID: CVE-2011-1141
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14974
Common Vulnerability Exposure (CVE) ID: CVE-2011-1138
BugTraq ID: 46636
http://www.securityfocus.com/bid/46636
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16299
XForce ISS Database: wireshark6lowpan-bo(65783)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65783
Common Vulnerability Exposure (CVE) ID: CVE-2011-1139
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14997
XForce ISS Database: wireshark-pcapng-dos(65779)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65779
Common Vulnerability Exposure (CVE) ID: CVE-2011-0713
46416
http://www.securityfocus.com/bid/46416
[oss-security] 20110216 wireshark dct3trace buffer overflow
http://openwall.com/lists/oss-security/2011/02/16/13
http://anonsvn.wireshark.org/viewvc?view=rev&revision=35953
https://bugzilla.redhat.com/show_bug.cgi?id=678198
oval:org.mitre.oval:def:14766
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14766
wireshark-nokiadct3-bo(65780)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65780
wireshark-visualc-bo(65460)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65460
Common Vulnerability Exposure (CVE) ID: CVE-2010-2287
BugTraq ID: 40728
http://www.securityfocus.com/bid/40728
http://www.mandriva.com/security/advisories?name=MDVSA-2010:113
http://www.mandriva.com/security/advisories?name=MDVSA-2010:144
http://www.openwall.com/lists/oss-security/2010/06/11/1
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11836
http://secunia.com/advisories/40112
SuSE Security Announcement: SUSE-SR:2011:001 (Google Search)
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://www.vupen.com/english/advisories/2010/1418
Common Vulnerability Exposure (CVE) ID: CVE-2010-2286
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11792
Common Vulnerability Exposure (CVE) ID: CVE-2010-2284
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11888
Common Vulnerability Exposure (CVE) ID: CVE-2010-2283
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11608
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.