Bugzilla – Bug 678569
VUL-0: wireshark: crash via SMB or CLDAP packet
Last modified: 2011-04-14 06:36:13 UTC
Your friendly security team received the following report via mitre. Please respond ASAP. The issue is public. -------8<------- ====================================================== Name: CVE-2011-1140 Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet. Reference: CONFIRM: http://www.wireshark.org/docs/relnotes/wireshark-1.4.4.html Reference: CONFIRM: http://www.wireshark.org/docs/relnotes/wireshark-1.2.15.html Reference: CONFIRM: http://anonsvn.wireshark.org/viewvc?view=rev&revision=36029 Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5717 Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2011-04.html Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2011-03.html
Update released for: wireshark, wireshark-debuginfo, wireshark-debugsource, wireshark-devel Products: SLE-DEBUGINFO 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLE-DESKTOP 11-SP1 (i386, x86_64) SLE-SDK 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLES4VMWARE 11-SP1 (i386, x86_64)
Update released for: wireshark, wireshark-debuginfo, wireshark-devel Products: SLE-DESKTOP 10-SP3 (i386, x86_64) SLE-SAP-APL 10-SP3 (x86_64) SLE-SDK 10-SP3 (i386, ia64, ppc, s390x, x86_64) SLE-SERVER 10-SP3 (i386, ia64, ppc, s390x, x86_64)
Update released for: wireshark, wireshark-debuginfo, wireshark-devel Products: SLE-DESKTOP 10-SP4 (i386, x86_64) SLE-SDK 10-SP4 (i386, ia64, ppc, s390x, x86_64) SLE-SERVER 10-SP4 (i386, ia64, ppc, s390x, x86_64)
This bug (678569) was mentioned in https://build.opensuse.org/request/show/66852
Box received updates too. Closing.