Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4F0E7986.20503@redhat.com>
Date: Wed, 11 Jan 2012 23:11:18 -0700
From: Kurt Seifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
CC: "Steven M. Christey" <coley@...us.mitre.org>,
        Agostino Sarubbo <ago@...too.org>
Subject: Re: CVE request: Wireshark multiple vulnerabilities

On 01/11/2012 07:20 PM, Steven M. Christey wrote:
>
> On Wed, 11 Jan 2012, Kurt Seifried wrote:
>
>> On 01/11/2012 09:19 AM, Agostino Sarubbo wrote:
>>> According to secunia advisory: https://secunia.com/advisories/47494/ :
>>>
>>> Multiple vulnerabilities have been reported in Wireshark, which can be
>>> exploited by malicious people to cause a DoS (Denial of Service) and
>>> compromise a user's system.
>>>
>>> 1) NULL pointer dereference errors when reading certain packet
>>> information can
>>> be exploited to cause a crash.
>
> In this case, if a network monitor can be crashed, an attacker might
> be able to launch an attack undetected.  As such, NULL pointer
> dereferences and other crashers in security-relevant products often
> count for CVEs, so Kurt, please assign one for this.
>
> See http://www.openwall.com/lists/oss-security/2011/09/14/9 for
> further explanation from me.
>
> - Steve
>From what I read the first #1 and #2 (secunia) map to wireshark
wnpa-sec-2012-02.html and wnpa-sec-2012-03.html respectively, so they
should be all good? Or did I misread it (this is entirely possible =).

-- 

-- Kurt Seifried / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.