RHSA-2013:0125: Moderate: wireshark security, bug fix, and enhancement update
Wireshark, previously known as Ethereal, is a network protocol analyzer. Itis used to capture and browse the traffic running on a computer network.A heap-based buffer overflow flaw was found in the way Wireshark handledEndace ERF (Extensible Record Format) capture files. If Wireshark opened aspecially-crafted ERF capture file, it could crash or, possibly, executearbitrary code as the user running Wireshark. (CVE-2011-4102)Several denial of service flaws were found in Wireshark. Wireshark couldcrash or stop responding if it read a malformed packet off a network, oropened a malicious dump file. (CVE-2011-1958, CVE-2011-1959, CVE-2011-2175,CVE-2011-2698, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066, CVE-2012-0067,CVE-2012-4285, CVE-2012-4289, CVE-2012-4290, CVE-2012-4291)The CVE-2011-1958, CVE-2011-1959, CVE-2011-2175, and CVE-2011-4102 issueswere discovered by Huzaifa Sidhpurwala of the Red Hat Security ResponseTeam.This update also fixes the following bugs: When Wireshark starts with the X11 protocol being tunneled through an SSH connection, it automatically prepares its capture filter to omit the SSHpackets. If the SSH connection was to a link-local IPv6 address includingan interface name (for example ssh -X [ipv6addr]%eth0), Wireshark parsedthis address erroneously, constructed an incorrect capture filter andrefused to capture packets. The "Invalid capture filter" message wasdisplayed. With this update, parsing of link-local IPv6 addresses is fixedand Wireshark correctly prepares a capture filter to omit SSH packets overa link-local IPv6 connection. (BZ#438473) Previously, Wireshark's column editing dialog malformed column names when they were selected. With this update, the dialog is fixed and no longerbreaks column names. (BZ#493693) Previously, TShark, the console packet analyzer, did not properly analyze the exit code of Dumpcap, Wireshark's packet capturing back end. As aresult, TShark returned exit code 0 when Dumpcap failed to parse itscommand-line arguments. In this update, TShark correctly propagates theDumpcap exit code and returns a non-zero exit code when Dumpcap fails.(BZ#580510) Previously, the TShark "-s" (snapshot length) option worked only for a value greater than 68 bytes. If a lower value was specified, TSharkcaptured just 68 bytes of incoming packets. With this update, the "-s"option is fixed and sizes lower than 68 bytes work as expected. (BZ#580513)This update also adds the following enhancement: In this update, support for the "NetDump" protocol was added. (BZ#484999) All users of Wireshark are advised to upgrade to these updated packages,which contain backported patches to correct these issues and add thisenhancement. All running instances of Wireshark must be restarted for theupdate to take effect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:0125?
The severity of RHSA-2013:0125 is rated as important due to the potential for a heap-based buffer overflow that could lead to remote code execution.
How do I fix RHSA-2013:0125?
To fix RHSA-2013:0125, update Wireshark to version 1.0.15-5.el5 or a later version.
Which versions of Wireshark are affected by RHSA-2013:0125?
All versions of Wireshark prior to 1.0.15-5.el5 are affected by RHSA-2013:0125.
What type of vulnerability is described in RHSA-2013:0125?
RHSA-2013:0125 describes a heap-based buffer overflow vulnerability in Wireshark.
Is RHSA-2013:0125 applicable to Wireshark-debuginfo packages?
Yes, RHSA-2013:0125 also affects the Wireshark-debuginfo packages prior to version 1.0.15-5.el5.