Solution
Please Install the Updated Packages.
Insight
This advisory updates wireshark to the latest version(s), fixing several security issues:
* The SMB dissector could dereference a NULL pointer. (Bug 4734) * J. Oquendo discovered that the ASN.1 BER dissector could overrun the stack.
* The SMB PIPE dissector could dereference a NULL pointer on some platforms.
* The SigComp Universal Decompressor Virtual Machine could go into an infinite loop. (Bug 4826)
* The SigComp Universal Decompressor Virtual Machine could overrun a buffer. (Bug 4837)
Affected
wireshark on Mandriva Linux 2009.1,
Mandriva Linux 2009.1/X86_64,
Mandriva Linux 2010.0,
Mandriva Linux 2010.0/X86_64,
Mandriva Enterprise Server 5,
Mandriva Enterprise Server 5/X86_64
Severity
Classification
-
CVE CVE-2010-2283, CVE-2010-2284, CVE-2010-2285, CVE-2010-2286, CVE-2010-2287 -
CVSS Base Score: 8.3
AV:A/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities