Package: wireshark
Version: 0.99.7-1
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for wireshark.

CVE-2008-1072[0]:
| The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through
| 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause
| a denial of service (crash or memory consumption) via a malformed
| packet, possibly related to a Cairo library bug.

CVE-2008-1071[1]:
| The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through
| 0.99.7 allows remote attackers to cause a denial of service (crash)
| via a malformed packet.

CVE-2008-1070[2]:
| The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through
| 0.99.7 allows remote attackers to cause a denial of service (crash)
| via a malformed packet.

If you fix these vulnerabilities please also include the CVE ids
in your changelog entry.

For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1072
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1071
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1070

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpUEnEK1wVHI.pgp
Description: PGP signature

Reply via email to