Summary
The remote host is missing an update to wireshark
announced via advisory MDVSA-2009:088.
Solution
To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2009:088 http://www.wireshark.org/security/wnpa-sec-2009-02.html
Insight
Multiple vulnerabilities has been identified and corrected in wireshark:
o The PROFINET dissector was vulnerable to a format string overflow (CVE-2009-1210).
o The Check Point High-Availability Protocol (CPHAP) dissecto could crash (CVE-2009-1268).
o Wireshark could crash while loading a Tektronix .rf5 file (CVE-2009-1269).
This update provides Wireshark 1.0.7, which is not vulnerable to these issues.
Affected: 2008.1, 2009.0, Corporate 4.0
Severity
Classification
-
CVE CVE-2009-1210, CVE-2009-1268, CVE-2009-1269 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities