Skip to navigation

Security Advisory Moderate: wireshark security update

Advisory: RHSA-2008:0059-6
Type: Security Advisory
Severity: Moderate
Issued on: 2008-01-21
Last updated on: 2008-01-21
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
CVEs (cve.mitre.org): CVE-2007-3389
CVE-2007-3390
CVE-2007-3391
CVE-2007-3392
CVE-2007-3393
CVE-2007-6113
CVE-2007-6114
CVE-2007-6115
CVE-2007-6117
CVE-2007-6118
CVE-2007-6120
CVE-2007-6121
CVE-2007-6450
CVE-2007-6451

Details

Updated wireshark packages that fix several security issues are now
available for Red Hat Enterprise Linux 3.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Several flaws were found in Wireshark. Wireshark could crash or possibly
execute arbitrary code as the user running Wireshark if it read a malformed
packet off the network. (CVE-2007-6114, CVE-2007-6115, CVE-2007-6117)

Several denial of service bugs were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off the network.
(CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392, CVE-2007-3392,
CVE-2007-3393, CVE-2007-6113, CVE-2007-6118, CVE-2007-6120, CVE-2007-6121,
CVE-2007-6450, CVE-2007-6451)

As well, Wireshark switched from using net-snmp to libsmi, which is
included in this errata.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 0.99.7, and resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/SRPMS/libsmi-0.4.5-3.el3.src.rpm
Missing file
    MD5: a1a35fbf382231df902c424b2959038b
wireshark-0.99.7-EL3.1.src.rpm
File outdated by:  RHSA-2010:0625
    MD5: 40154e7966ee02ff32939b991e562e20
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/i386/libsmi-0.4.5-3.el3.i386.rpm
Missing file
    MD5: 2fe6cfc58df4d4bb871d874e602ecb16
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/i386/libsmi-devel-0.4.5-3.el3.i386.rpm
Missing file
    MD5: b1f885bb55a7e0e52dad4be001b1fc4d
wireshark-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: d15af12a3d4bfecd36d07e1cae679d3f
wireshark-gnome-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: 86042a624170d835275775d55d767855
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/x86_64/libsmi-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: a93c0a4fb355ff44b23f78c7361798f1
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/x86_64/libsmi-devel-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: 2bdf988fc0fae1d716b60f10fa48d975
wireshark-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 711f1960c3e51e6ebad47ee28931d2b4
wireshark-gnome-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: cde1c0df4410fa25cc88175b70520010
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/SRPMS/libsmi-0.4.5-3.el3.src.rpm
Missing file
    MD5: a1a35fbf382231df902c424b2959038b
wireshark-0.99.7-EL3.1.src.rpm
File outdated by:  RHSA-2010:0625
    MD5: 40154e7966ee02ff32939b991e562e20
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/i386/libsmi-0.4.5-3.el3.i386.rpm
Missing file
    MD5: 2fe6cfc58df4d4bb871d874e602ecb16
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/i386/libsmi-devel-0.4.5-3.el3.i386.rpm
Missing file
    MD5: b1f885bb55a7e0e52dad4be001b1fc4d
wireshark-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: d15af12a3d4bfecd36d07e1cae679d3f
wireshark-gnome-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: 86042a624170d835275775d55d767855
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/ia64/libsmi-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 4ab4a706a1e91272ec4d2165d56397e8
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/ia64/libsmi-devel-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 23178622baab998513961b9d6f8382eb
wireshark-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 847c5d06a19faf0f1c16b1f129f1910c
wireshark-gnome-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 1af3f5cf89ee43973d86c4b9e0bc34ba
 
PPC:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/ppc/libsmi-0.4.5-3.el3.ppc.rpm
Missing file
    MD5: 3fe4e4705626e9739022fb32ca036d89
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/ppc/libsmi-devel-0.4.5-3.el3.ppc.rpm
Missing file
    MD5: 4b969e679c4d5d27baa0ce651599cb69
wireshark-0.99.7-EL3.1.ppc.rpm
File outdated by:  RHSA-2010:0625
    MD5: cc334ee4a044374a9b05e39f233073a7
wireshark-gnome-0.99.7-EL3.1.ppc.rpm
File outdated by:  RHSA-2010:0625
    MD5: 65dff8a05d90742c7f8f9e0e34c4aa69
 
s390:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/s390/libsmi-0.4.5-3.el3.s390.rpm
Missing file
    MD5: b9d2cec118439eb5fa3123f49fd2f3f2
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/s390/libsmi-devel-0.4.5-3.el3.s390.rpm
Missing file
    MD5: c2ce4b16b62141ee17202dc457d29ba3
wireshark-0.99.7-EL3.1.s390.rpm
File outdated by:  RHSA-2010:0625
    MD5: 17a4d67e743c762ab8c2904302d2d1f8
wireshark-gnome-0.99.7-EL3.1.s390.rpm
File outdated by:  RHSA-2010:0625
    MD5: 94d46d5d064ec3cd061a589d0edd9843
 
s390x:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/s390x/libsmi-0.4.5-3.el3.s390x.rpm
Missing file
    MD5: 22615dfef18fb39a787ea830d45833de
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/s390x/libsmi-devel-0.4.5-3.el3.s390x.rpm
Missing file
    MD5: b2c00e98068ad206515ba3813db7740c
wireshark-0.99.7-EL3.1.s390x.rpm
File outdated by:  RHSA-2010:0625
    MD5: 6497eb4895df42a41af6fc3152286a3a
wireshark-gnome-0.99.7-EL3.1.s390x.rpm
File outdated by:  RHSA-2010:0625
    MD5: 9f04cc168e8c01c360af973c8ff1334a
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/x86_64/libsmi-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: a93c0a4fb355ff44b23f78c7361798f1
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/x86_64/libsmi-devel-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: 2bdf988fc0fae1d716b60f10fa48d975
wireshark-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 711f1960c3e51e6ebad47ee28931d2b4
wireshark-gnome-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: cde1c0df4410fa25cc88175b70520010
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/SRPMS/libsmi-0.4.5-3.el3.src.rpm
Missing file
    MD5: a1a35fbf382231df902c424b2959038b
wireshark-0.99.7-EL3.1.src.rpm
File outdated by:  RHSA-2010:0625
    MD5: 40154e7966ee02ff32939b991e562e20
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/i386/libsmi-0.4.5-3.el3.i386.rpm
Missing file
    MD5: 2fe6cfc58df4d4bb871d874e602ecb16
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/i386/libsmi-devel-0.4.5-3.el3.i386.rpm
Missing file
    MD5: b1f885bb55a7e0e52dad4be001b1fc4d
wireshark-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: d15af12a3d4bfecd36d07e1cae679d3f
wireshark-gnome-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: 86042a624170d835275775d55d767855
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/ia64/libsmi-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 4ab4a706a1e91272ec4d2165d56397e8
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/ia64/libsmi-devel-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 23178622baab998513961b9d6f8382eb
wireshark-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 847c5d06a19faf0f1c16b1f129f1910c
wireshark-gnome-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 1af3f5cf89ee43973d86c4b9e0bc34ba
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/x86_64/libsmi-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: a93c0a4fb355ff44b23f78c7361798f1
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/x86_64/libsmi-devel-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: 2bdf988fc0fae1d716b60f10fa48d975
wireshark-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 711f1960c3e51e6ebad47ee28931d2b4
wireshark-gnome-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: cde1c0df4410fa25cc88175b70520010
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/SRPMS/libsmi-0.4.5-3.el3.src.rpm
Missing file
    MD5: a1a35fbf382231df902c424b2959038b
wireshark-0.99.7-EL3.1.src.rpm
File outdated by:  RHSA-2010:0625
    MD5: 40154e7966ee02ff32939b991e562e20
 
IA-32:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/i386/libsmi-0.4.5-3.el3.i386.rpm
Missing file
    MD5: 2fe6cfc58df4d4bb871d874e602ecb16
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/i386/libsmi-devel-0.4.5-3.el3.i386.rpm
Missing file
    MD5: b1f885bb55a7e0e52dad4be001b1fc4d
wireshark-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: d15af12a3d4bfecd36d07e1cae679d3f
wireshark-gnome-0.99.7-EL3.1.i386.rpm
File outdated by:  RHSA-2010:0625
    MD5: 86042a624170d835275775d55d767855
 
IA-64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/ia64/libsmi-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 4ab4a706a1e91272ec4d2165d56397e8
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/ia64/libsmi-devel-0.4.5-3.el3.ia64.rpm
Missing file
    MD5: 23178622baab998513961b9d6f8382eb
wireshark-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 847c5d06a19faf0f1c16b1f129f1910c
wireshark-gnome-0.99.7-EL3.1.ia64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 1af3f5cf89ee43973d86c4b9e0bc34ba
 
x86_64:
ftp://updates.redhat.com/rhn/public/NULL/libsmi/0.4.5-3.el3/x86_64/libsmi-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: a93c0a4fb355ff44b23f78c7361798f1
ftp://updates.redhat.com/rhn/public/NULL/libsmi-devel/0.4.5-3.el3/x86_64/libsmi-devel-0.4.5-3.el3.x86_64.rpm
Missing file
    MD5: 2bdf988fc0fae1d716b60f10fa48d975
wireshark-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: 711f1960c3e51e6ebad47ee28931d2b4
wireshark-gnome-0.99.7-EL3.1.x86_64.rpm
File outdated by:  RHSA-2010:0625
    MD5: cde1c0df4410fa25cc88175b70520010
 

Bugs fixed (see bugzilla for more information)

245796 - CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic
245797 - CVE-2007-3391 Wireshark loops infinitely when inspecting DCP ETSI traffic
245798 - CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic
246221 - CVE-2007-3393 Wireshark corrupts the stack when inspecting BOOTP traffic
246225 - CVE-2007-3390 Wireshark crashes when inspecting iSeries traffic
246229 - CVE-2007-3392 Wireshark crashes when inspecting MMS traffic
397281 - CVE-2007-6113 wireshark DNP3 flaws
397291 - CVE-2007-6114 wireshark SSL and OS/400 trace flaws
397311 - CVE-2007-6115 wireshark ANSI MAP flaws
397331 - CVE-2007-6117 wireshark HTTP dissector flaws
397341 - CVE-2007-6118 wireshark MEGACO dissector flaws
397361 - CVE-2007-6120 wireshark Bluetooth SDP dissector flaws
397371 - CVE-2007-6121 wireshark RPC Portmap flaws
426337 - Wireshare rebase requires new libsmi package adding to rhel3
427253 - CVE-2007-6450 wireshark RPL dissector crash
427254 - CVE-2007-6451 wireshark CIP dissector crash


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/