Summary
Multiple vulnerabilities were discovered in Wireshark:
CVE-2014-2281
Moshe Kaplan discovered that the NFS dissector could be crashed, resulting in denial of service.
CVE-2014-2283
It was discovered that the RLC dissector could be crashed, resulting in denial of service.
CVE-2014-2299
Wesley Neelen discovered a buffer overflow in the MPEG file parser, which could lead to the execution of arbitrary code.
Solution
For the oldstable distribution (squeeze), these problems have been fixed in version 1.2.11-6+squeeze14.
For the stable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy10.
For the unstable distribution (sid), these problems have been fixed in version 1.10.6-1.
We recommend that you upgrade your wireshark packages.
Insight
Wireshark is a network 'sniffer' - a tool that captures and analyzes packets off the wire. Wireshark can decode too many protocols to list here.
Affected
wireshark on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2014-2281, CVE-2014-2283, CVE-2014-2299 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities