[SECURITY] Fedora 13 Update: wireshark-1.2.10-1.fc13
updates at fedoraproject.org
updates at fedoraproject.org
Thu Sep 2 20:45:30 UTC 2010
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-13416
2010-08-24 20:36:29
--------------------------------------------------------------------------------
Name : wireshark
Product : Fedora 13
Version : 1.2.10
Release : 1.fc13
URL : http://www.wireshark.org/
Summary : Network traffic analyzer
Description :
Wireshark is a network traffic analyzer for Unix-ish operating systems.
This package lays base for libpcap, a packet capture and filtering
library, contains command-line utilities, contains plugins and
documentation for wireshark. A graphical user interface is packaged
separately to GTK+ package.
--------------------------------------------------------------------------------
Update Information:
Update to upstream version 1.2.10: *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.9.html *
http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html fixing multiple
security issues: * http://www.wireshark.org/security/wnpa-sec-2010-06.html *
http://www.wireshark.org/security/wnpa-sec-2010-08.html
--------------------------------------------------------------------------------
ChangeLog:
* Tue Aug 24 2010 Jan Safranek <jsafrane at redhat.com> - 1.2.10-1
- upgrade to 1.2.10
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html
- Resolves: #625940 CVE-2010-2287 CVE-2010-2286 CVE-2010-2284 CVE-2010-2283
* Mon May 17 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-3
- removing traling bracket from python_sitearch (#592391)
* Fri May 7 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-2
- add libtool patch
* Fri May 7 2010 Radek Vokal <rvokal at redhat.com> - 1.2.8-1
- use sitearch instead of sitelib to avoid pyo and pyc conflicts
- upgrade to 1.2.8
- see http://www.wireshark.org/docs/relnotes/wireshark-1.2.8.html
- rebuild with GeoIP support (needs to be turned on in IP protocol preferences)
- bring back -pie
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #604308 - CVE-2010-2287 CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns
https://bugzilla.redhat.com/show_bug.cgi?id=604308
[ 2 ] Bug #604302 - CVE-2010-2286 wireshark: SigComp UDVM dissector infinite loop
https://bugzilla.redhat.com/show_bug.cgi?id=604302
[ 3 ] Bug #604292 - CVE-2010-2284 wireshark: ASN.1 BER dissector stack overrun
https://bugzilla.redhat.com/show_bug.cgi?id=604292
[ 4 ] Bug #604290 - CVE-2010-2283 wireshark: SMB dissector NULL pointer dereference
https://bugzilla.redhat.com/show_bug.cgi?id=604290
[ 5 ] Bug #623843 - CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities
https://bugzilla.redhat.com/show_bug.cgi?id=623843
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update wireshark' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
More information about the package-announce
mailing list