First published: Mon Jan 21 2008(Updated: )
Wireshark is a program for monitoring network traffic. Wireshark was<br>previously known as Ethereal.<br>Several flaws were found in Wireshark. Wireshark could crash or possibly<br>execute arbitrary code as the user running Wireshark if it read a malformed<br>packet off the network. (CVE-2007-6114, CVE-2007-6115, CVE-2007-6117)<br>Several denial of service bugs were found in Wireshark. Wireshark could<br>crash or stop responding if it read a malformed packet off the network.<br>(CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392, CVE-2007-3392,<br>CVE-2007-3393, CVE-2007-6113, CVE-2007-6118, CVE-2007-6120, CVE-2007-6121,<br>CVE-2007-6450, CVE-2007-6451)<br>As well, Wireshark switched from using net-snmp to libsmi, which is<br>included in this errata.<br>Users of wireshark should upgrade to these updated packages, which contain<br>Wireshark version 0.99.7, and resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2008:0059 is considered high due to the potential for crashes and arbitrary code execution.
To fix RHSA-2008:0059, update Wireshark to the latest version provided in the security advisory.
RHSA-2008:0059 addresses multiple flaws in Wireshark that can lead to application crashes and arbitrary code execution.
RHSA-2008:0059 affects multiple versions of Wireshark prior to the updated release.
No, using Wireshark without addressing RHSA-2008:0059 poses a significant security risk due to exploitable vulnerabilities.