Summary
Name: Multiple problems in Wireshark® versions 0.99.2 to 0.99.8
Docid: wnpa-sec-2008-02
Date: March 31, 2008
Versions affected: 0.99.2 up to and including 0.99.8
Details
Description
Wireshark 1.0.0 fixes the following vulnerabilities:
-
The X.509sat dissector could crash.
(Bug 2329)
Versions affected: 0.99.5 to 0.99.8
-
The Roofnet dissector could crash on Windows, Solaris, and
other platforms.
(Bug 2331)
Versions affected: 0.99.5 to 0.99.8
-
The LDAP dissector could crash on Windows and other platforms.
(Bug 1613)
Versions affected: 0.99.2 to 0.99.8
-
The SCCP dissector could crash while using the "decode as" feature.
(Bug 2392)
Versions affected: 0.99.6 to 0.99.8
Impact
It may be possible to make Wireshark crashby injecting a purposefully malformed
packet onto the wire or by convincing someone to read a malformed packet trace
file.
Resolution
Upgrade to Wireshark 1.0.0 or later.
If are running Wireshark 0.99.8 or earlier and
cannot upgrade, you can work around each of the problems listed above
by doing the following:
- Disable the LDAP, Roofnet, and X.509sat dissectors:
- Select Analyze→Enabled Protocols... from the menu.
- Make sure "LDAP," "Roofnet," and "X509SAT" are un-checked.
- Click "Save", then click "OK".