Debian Security Advisory
DSA-2395-1 wireshark -- buffer underflow
- Date Reported:
- 27 Jan 2012
- Affected Packages:
- wireshark
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2011-3483, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066, CVE-2012-0067, CVE-2012-0068.
- More information:
-
Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code (CVE-2012-0068).
This update also addresses several bugs, which can lead to crashes of Wireshark. These are not treated as security issues, but are fixed nonetheless if security updates are scheduled: CVE-2011-3483, CVE-2012-0041, CVE-2012-0042, CVE-2012-0066 and CVE-2012-0067.
For the stable distribution (squeeze), this problem has been fixed in version 1.2.11-6+squeeze6.
For the unstable distribution (sid), this problem has been fixed in version 1.6.5-1.
We recommend that you upgrade your wireshark packages.