Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.64.1101121750300.17455@faron.mitre.org>
Date: Wed, 12 Jan 2011 17:51:08 -0500 (EST)
From: "Steven M. Christey" <coley@...-smtp.mitre.org>
To: oss-security@...ts.openwall.com
Subject: CVE assignments for Wireshark


CVE-2011-0444 - MAC-LTE

CVE-2011-0445 - ASN.1 BER



======================================================
Name: CVE-2011-0444
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0444
Reference: MISC:https://bugs.wireshark.org/bugzilla/attachment.cgi?id=5676
Reference: CONFIRM:http://www.wireshark.org/security/wnpa-sec-2011-01.html
Reference: CONFIRM:http://www.wireshark.org/security/wnpa-sec-2011-02.html
Reference: CONFIRM:https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5530
Reference: VUPEN:ADV-2011-0079
Reference: URL:http://www.vupen.com/english/advisories/2011/0079

Buffer overflow in the MAC-LTE dissector
(epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through 1.2.13
and 1.4.0 through 1.4.2 allows remote attackers to cause a denial of
service (crash) and possibly execute arbitrary code via a large number
of RARs.


======================================================
Name: CVE-2011-0445
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0445
Reference: CONFIRM:http://www.wireshark.org/security/wnpa-sec-2011-02.html
Reference: CONFIRM:https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5537
Reference: VUPEN:ADV-2011-0079
Reference: URL:http://www.vupen.com/english/advisories/2011/0079

The ASN.1 BER dissector in Wireshark 1.4.0 through 1.4.2 allows remote
attackers to cause a denial of service (assertion failure) via crafted
packets, as demonstrated by fuzz-2010-12-30-28473.pcap.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.