RHSA-2008:0058: Moderate: wireshark security update
Wireshark is a program for monitoring network traffic. Wireshark waspreviously known as Ethereal.Several flaws were found in Wireshark. Wireshark could crash or possiblyexecute arbitrary code as the user running Wireshark if it read a malformedpacket off the network. (CVE-2007-6112, CVE-2007-6114, CVE-2007-6115,CVE-2007-6117)Several denial of service bugs were found in Wireshark. Wireshark couldcrash or stop responding if it read a malformed packet off the network.(CVE-2007-6111, CVE-2007-6113, CVE-2007-6116, CVE-2007-6118, CVE-2007-6119,CVE-2007-6120, CVE-2007-6121, CVE-2007-6438, CVE-2007-6439, CVE-2007-6441,CVE-2007-6450, CVE-2007-6451)As well, Wireshark switched from using net-snmp to libsmi, which isincluded in this errata.Users of wireshark should upgrade to these updated packages, which containWireshark version 0.99.7, and resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0058?
The severity of RHSA-2008:0058 is classified as critical due to the potential for arbitrary code execution.
How do I fix RHSA-2008:0058?
To fix RHSA-2008:0058, update Wireshark and libsmi to the latest recommended versions.
What software is affected by RHSA-2008:0058?
The affected software for RHSA-2008:0058 includes Wireshark versions up to 0.99.7-1.el5 and libsmi versions up to 0.4.5-2.el5.
What can happen if RHSA-2008:0058 is exploited?
If exploited, RHSA-2008:0058 could lead to a crash of the Wireshark application or arbitrary code execution by an attacker.
Is RHSA-2008:0058 relevant for all systems?
RHSA-2008:0058 is specifically relevant for systems running affected versions of Wireshark and libsmi, particularly on Red Hat Enterprise Linux 5 and 4.