Wireshark: Multiple vulnerabilities Multiple vulnerabilities have been discovered in Wireshark which allow for Denial of Service or remote code execution. wireshark 2009-06-30 2009-06-30 242996 248425 258013 264571 271062 remote 1.0.8 1.0.8

Wireshark is a versatile network protocol analyzer.

Multiple vulnerabilities have been discovered in Wireshark:

A remote attacker could exploit these vulnerabilities by sending specially crafted packets on a network being monitored by Wireshark or by enticing a user to read a malformed packet trace file which can trigger a Denial of Service (application crash or excessive CPU and memory usage) and possibly allow for the execution of arbitrary code with the privileges of the user running Wireshark.

There is no known workaround at this time.

All Wireshark users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-1.0.8"
CVE-2008-4680 CVE-2008-4681 CVE-2008-4682 CVE-2008-4683 CVE-2008-4684 CVE-2008-4685 CVE-2008-5285 CVE-2008-6472 CVE-2009-0599 CVE-2009-0600 CVE-2009-0601 CVE-2009-1210 CVE-2009-1266 CVE-2009-1268 CVE-2009-1269 CVE-2009-1829 craig craig