Debian Security Advisory

DSA-2825-1 wireshark -- several vulnerabilities

Date Reported:
20 Dec 2013
Affected Packages:
wireshark
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-7113, CVE-2013-7114.
More information:

Laurent Butti and Garming Sam discovered multiple vulnerabilities in the dissectors for NTLMSSPv2 and BSSGP, which could lead to denial of service or the execution of arbitrary code.

For the stable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy9.

For the unstable distribution (sid), these problems have been fixed in version 1.10.4-1.

We recommend that you upgrade your wireshark packages.