From owner-freebsd-ports-bugs@FreeBSD.ORG Tue May 5 21:10:03 2009 Return-Path: Delivered-To: freebsd-ports-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 96CF610656C6; Tue, 5 May 2009 21:10:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 7106F8FC0C; Tue, 5 May 2009 21:10:03 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.3/8.14.3) with ESMTP id n45LA3Wg089013; Tue, 5 May 2009 21:10:03 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.3/8.14.3/Submit) id n45LA365089012; Tue, 5 May 2009 21:10:03 GMT (envelope-from gnats) Resent-Date: Tue, 5 May 2009 21:10:03 GMT Resent-Message-Id: <200905052110.n45LA365089012@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@freebsd.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Cc: marcus@freebsd.org, rea-fbsd@codelabs.ru Resent-Reply-To: FreeBSD-gnats-submit@freebsd.org, Eygene Ryabinkin Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 1FE131065670 for ; Tue, 5 May 2009 21:03:42 +0000 (UTC) (envelope-from rea-fbsd@codelabs.ru) Received: from 0.mx.codelabs.ru (0.mx.codelabs.ru [144.206.177.45]) by mx1.freebsd.org (Postfix) with ESMTP id C37808FC16 for ; Tue, 5 May 2009 21:03:41 +0000 (UTC) (envelope-from rea-fbsd@codelabs.ru) Received: from amnesiac.at.no.dns ([91.78.118.163]) by 0.mx.codelabs.ru with esmtps (TLSv1:CAMELLIA256-SHA:256) id 1M1Rng-000Cia-Gm for FreeBSD-gnats-submit@freebsd.org; Wed, 06 May 2009 01:03:40 +0400 Message-Id: <20090505195232.8D36A1725F@amnesiac.at.no.dns> Date: Tue, 5 May 2009 23:52:32 +0400 (MSD) From: Eygene Ryabinkin To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.113 X-GNATS-Notify: marcus@freebsd.org, rea-fbsd@codelabs.ru Cc: Subject: ports/134245: [vuxml] net/wireshark: document security issues fixed in 1.0.7 X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Eygene Ryabinkin List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 05 May 2009 21:10:04 -0000 >Number: 134245 >Category: ports >Synopsis: [vuxml] net/wireshark: document security issues fixed in 1.0.7 >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Tue May 05 21:10:02 UTC 2009 >Closed-Date: >Last-Modified: >Originator: Eygene Ryabinkin >Release: FreeBSD 8.0-CURRENT amd64 >Organization: Code Labs >Environment: System: FreeBSD 8.0-CURRENT amd64 >Description: 3 vulnerabilities (and one concerning Windows, but I'm not counting it here) were fixed in wireshark 1.0.7: [1], [2]. >How-To-Repeat: [1] http://www.wireshark.org/docs/relnotes/wireshark-1.0.7.html [2] http://www.wireshark.org/security/wnpa-sec-2009-02.html >Fix: Port was already updated, we're fine here. The following VuXML entry should be evaluated and added: --- vuln.xml begins here --- wireshark -- multiple vulnerabilities wireshark wireshark-lite 0.99.61.0.7

Wireshark team reports:

Wireshark 1.0.7 fixes the following vulnerabilities:

  • The PROFINET dissector was vulnerable to a format string overflow. (Bug 3382) Versions affected: 0.99.6 to 1.0.6, CVE-2009-1210.
  • The Check Point High-Availability Protocol (CPHAP) dissector could crash. (Bug 3269) Versions affected: 0.9.6 to 1.0.6; CVE-2009-1268.
  • Wireshark could crash while loading a Tektronix .rf5 file. (Bug 3366) Versions affected: 0.99.6 to 1.0.6, CVE-2009-1269.
CVE-2009-1210 CVE-2009-1268 CVE-2009-1269 34291 34457 http://www.wireshark.org/security/wnpa-sec-2009-02.html 2009-04-06 TODAY
--- vuln.xml ends here --- >Release-Note: >Audit-Trail: >Unformatted: