Summary
The remote host is missing an update to wireshark
announced via advisory DSA 2395-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202395-1
Insight
Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code (CVE-2012-0068)
This update also addresses several bugs, which can lead to crashes of Wireshark. These are not treated as security issues, but are fixed nonetheless if security updates are scheduled: CVE-2011-3483, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066 and CVE-2012-0067.
For the stable distribution (squeeze), this problem has been fixed in version 1.2.11-6+squeeze6.
For the unstable distribution (sid), this problem has been fixed in version 1.6.5-1.
We recommend that you upgrade your wireshark packages.
Severity
Classification
-
CVE CVE-2011-3483, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066, CVE-2012-0067, CVE-2012-0068 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities