<?xml version="1.0" encoding="utf-8"?>
<glsa id="200909-16">
<title>Wireshark: Denial of Service</title>
Multiple vulnerabilities have been discovered in Wireshark which allow for
Denial of Service.
<product type="ebuild">wireshark</product>
<announced>September 13, 2009</announced>
<revised>September 13, 2009: 01</revised>
<package name="net-analyzer/wireshark" auto="yes" arch="*">
<unaffected range="ge">1.2.1</unaffected>
<vulnerable range="lt">1.2.1</vulnerable>
Wireshark is a versatile network protocol analyzer.
Multiple vulnerabilities were discovered in Wireshark:
buffer overflow in the IPMI dissector related to an array index error
<li>Multiple unspecified vulnerabilities in the
Bluetooth L2CAP, RADIUS, and MIOP dissectors (CVE-2009-2560).</li>
<li>An unspecified vulnerability in the sFlow dissector
<li>An unspecified vulnerability in the AFS
dissector (CVE-2009-2562).</li>
<li>An unspecified vulnerability in the
Infiniband dissector when running on unspecified platforms
<impact type="normal">
A remote attacker could exploit these vulnerabilities by sending
specially crafted packets on a network being monitored by Wireshark or
by enticing a user to read a malformed packet trace file to cause a
Denial of Service.
There is no known workaround at this time.
All Wireshark users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=net-analyzer/wireshark-1.2.1&quot;</code>
<uri link="">CVE-2009-2559</uri>
<uri link="">CVE-2009-2560</uri>
<uri link="">CVE-2009-2561</uri>
<uri link="">CVE-2009-2562</uri>
<uri link="">CVE-2009-2563</uri>
<metadata tag="requester" timestamp="Tue, 25 Aug 2009 10:03:54 +0000">
<metadata tag="submitter" timestamp="Tue, 25 Aug 2009 13:10:41 +0000">
<metadata tag="bugReady" timestamp="Tue, 25 Aug 2009 13:28:12 +0000">