Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Reply to this topicStart new topic
> Wireshark updated
AplusWebMaster
post Feb 28 2008, 05:59 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

Wireshark multiple vulns - update available
- http://secunia.com/advisories/29156/
Release Date: 2008-02-28
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
Software: Wireshark (formerly Ethereal) 0.x
...The vulnerabilities are reported in various versions prior to 0.99.8.
Solution: Update to version 0.99.8.
http://www.wireshark.org/download.html

ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Mar 28 2008, 04:47 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

- http://www.wireshark.org/security/wnpa-sec-2008-02.html
Name: Multiple problems in Wireshark®versions 0.99.2 to 0.99.8
Docid: wnpa-sec-2008-02
Date: March 31, 2008 -?-
Versions affected: 0.99.2 up to and including 0.99.8 ...
Impact:
It may be possible to make Wireshark crash by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Resolution: Upgrade to Wireshark 1.0.0 or later.
If are running Wireshark 0.99.8 or earlier and cannot upgrade, you can work around each of the problems listed above by doing the following:
* Disable the LDAP, Roofnet, and X.509sat dissectors:
o Select Analyze→Enabled Protocols... from the menu.
o Make sure "LDAP," "Roofnet," and "X509SAT" are un-checked.
o Click "Save", then click "OK"...
- http://www.wireshark.org/download.html
"...current stable release of Wireshark is 0.99.8..." (03.28.2008)

- http://secunia.com/advisories/29569/
Release Date: 2008-03-28
Critical: Moderately critical
Impact: DoS
Where: From -remote-
Solution Status: Unpatched
...The vulnerabilities are reported in various versions prior to 1.0.0.
Solution: Fixed in an -upcoming- version 1.0.0.

ph34r.gif

This post has been edited by AplusWebMaster: Mar 28 2008, 04:48 AM
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Mar 31 2008, 04:45 PM
Post #3


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

Wireshark 1.0 released
- http://www.wireshark.org/
Mar 31, 2008 - "...In this release:
Security-related vulnerabilities in the X.509sat, Roofnet, LDAP, and SCCP dissectors have been fixed. See the advisory for details: http://www.wireshark.org/security/wnpa-sec-2008-02.html

Download:
- http://www.wireshark.org/download.html
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Jul 1 2008, 11:55 AM
Post #4


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

Wireshark multiple vulns - update available
- http://secunia.com/advisories/30886/
Release Date: 2008-07-01
Critical: Moderately critical
Impact: Exposure of sensitive information, DoS
Where: From remote
Solution Status: Vendor Patch
Software: Wireshark (formerly Ethereal) 0.x, Wireshark 1.x
Solution: Update to version 1.0.1...
Original Advisory: http://www.wireshark.org/security/wnpa-sec-2008-03.html

The current stable release of Wireshark is 1.0.1. It supersedes all previous releases...
- http://www.wireshark.org/download.html

ph34r.gif
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Jul 11 2008, 11:14 AM
Post #5


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

Wireshark v1.0.2 released
- http://secunia.com/advisories/31044/
Release Date: 2008-07-11
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
...The vulnerability is reported in versions 0.8.19 to 1.0.1.
Solution:
Update to version 1.0.2.
http://www.wireshark.org/download.html

> http://www.wireshark.org/security/wnpa-sec-2008-04.html

//
Go to the top of the page
 
+Quote Post
AplusWebMaster
post Sep 4 2008, 05:29 AM
Post #6


AplusWebMaster
*****

Group: Authentic Member
Posts: 3,657
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: WinXP



FYI...

Wireshark v1.0.3 released
- http://secunia.com/advisories/31674/
Release Date: 2008-09-04
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch
Software: Wireshark (formerly Ethereal) 0.x, Wireshark 1.x...
Solution: Update to version 1.0.3.
http://www.wireshark.org/download.html

- http://www.wireshark.org/security/wnpa-sec-2008-05.html

- http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3146

ph34r.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts  
1 Arrone 28 Yesterday, 04:58 PM
Last post by: LDTate
No New Posts
2 AplusWebMaster 337 26th September 2008 - 02:59 AM
Last post by: AplusWebMaster
No New Posts
5 AplusWebMaster 669 2nd September 2008 - 11:44 AM
Last post by: AplusWebMaster
No New Posts  
8 notesetter 427 10th July 2008 - 09:18 AM
Last post by: Digerati
No New Posts
0 AplusWebMaster 239 6th May 2008 - 06:10 AM
Last post by: AplusWebMaster

RSS Time is now: 7th October 2008 - 05:29 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy