RHSA-2008:0059: Moderate: wireshark security update
Wireshark is a program for monitoring network traffic. Wireshark waspreviously known as Ethereal.Several flaws were found in Wireshark. Wireshark could crash or possiblyexecute arbitrary code as the user running Wireshark if it read a malformedpacket off the network. (CVE-2007-6114, CVE-2007-6115, CVE-2007-6117)Several denial of service bugs were found in Wireshark. Wireshark couldcrash or stop responding if it read a malformed packet off the network.(CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392, CVE-2007-3392,CVE-2007-3393, CVE-2007-6113, CVE-2007-6118, CVE-2007-6120, CVE-2007-6121,CVE-2007-6450, CVE-2007-6451)As well, Wireshark switched from using net-snmp to libsmi, which isincluded in this errata.Users of wireshark should upgrade to these updated packages, which containWireshark version 0.99.7, and resolve these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0059?
The severity of RHSA-2008:0059 is considered high due to the potential for crashes and arbitrary code execution.
How do I fix RHSA-2008:0059?
To fix RHSA-2008:0059, update Wireshark to the latest version provided in the security advisory.
What vulnerabilities are addressed in RHSA-2008:0059?
RHSA-2008:0059 addresses multiple flaws in Wireshark that can lead to application crashes and arbitrary code execution.
Which versions of Wireshark are affected by RHSA-2008:0059?
RHSA-2008:0059 affects multiple versions of Wireshark prior to the updated release.
Is it safe to use Wireshark without addressing RHSA-2008:0059?
No, using Wireshark without addressing RHSA-2008:0059 poses a significant security risk due to exploitable vulnerabilities.