[SECURITY] Fedora 13 Update: wireshark-1.2.10-1.fc13

updates at fedoraproject.org updates at fedoraproject.org
Thu Sep 2 20:45:30 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-13416
2010-08-24 20:36:29
--------------------------------------------------------------------------------

Name        : wireshark
Product     : Fedora 13
Version     : 1.2.10
Release     : 1.fc13
URL         : http://www.wireshark.org/
Summary     : Network traffic analyzer
Description :
Wireshark is a network traffic analyzer for Unix-ish operating systems.

This package lays base for libpcap, a packet capture and filtering
library, contains command-line utilities, contains plugins and
documentation for wireshark. A graphical user interface is packaged
separately to GTK+ package.

--------------------------------------------------------------------------------
Update Information:

Update to upstream version 1.2.10:    *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.9.html  *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html    fixing multiple
security issues:    * http://www.wireshark.org/security/wnpa-sec-2010-06.html  *
http://www.wireshark.org/security/wnpa-sec-2010-08.html
--------------------------------------------------------------------------------
ChangeLog:

* Tue Aug 24 2010 Jan Safranek <jsafrane at redhat.com> - 1.2.10-1
- upgrade to 1.2.10
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html
- Resolves: #625940 CVE-2010-2287 CVE-2010-2286 CVE-2010-2284 CVE-2010-2283
* Mon May 17 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-3
- removing traling bracket from python_sitearch (#592391)
* Fri May  7 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-2
- add libtool patch
* Fri May  7 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-1
- use sitearch instead of sitelib to avoid pyo and pyc conflicts
- upgrade to 1.2.8
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.8.html
- rebuild with GeoIP support (needs to be turned on in IP protocol preferences)
- bring back -pie
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #604308 - CVE-2010-2287 CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns
        https://bugzilla.redhat.com/show_bug.cgi?id=604308
  [ 2 ] Bug #604302 - CVE-2010-2286 wireshark: SigComp UDVM dissector infinite loop
        https://bugzilla.redhat.com/show_bug.cgi?id=604302
  [ 3 ] Bug #604292 - CVE-2010-2284 wireshark: ASN.1 BER dissector stack overrun
        https://bugzilla.redhat.com/show_bug.cgi?id=604292
  [ 4 ] Bug #604290 - CVE-2010-2283 wireshark: SMB dissector NULL pointer dereference
        https://bugzilla.redhat.com/show_bug.cgi?id=604290
  [ 5 ] Bug #623843 - CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities
        https://bugzilla.redhat.com/show_bug.cgi?id=623843
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update wireshark' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list