漏洞信息详情
Wireshark IPSec ESP解析器缓冲区溢出漏洞
- CNNVD编号:CNNVD-200608-405
- 危害等级: 中危
- CVE编号:
CVE-2006-4331
- 漏洞类型:
资料不足
- 发布时间:
2006-08-24
- 威胁类型:
远程
- 更新时间:
2006-08-26
- 厂 商:
wireshark - 漏洞来源:
Wireshark http://w… -
漏洞简介
Wireshark是一款非常流行的网络协议分析工具,以前名为Ethereal。
Wireshark中存在多个安全漏洞,具体如下:
如果编译了ESP解密支持的话,IPSec ESP选择解析器中就会存在单字节缓冲区溢出漏洞;
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Wireshark Wireshark 0.7.9
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
Wireshark Wireshark 0.8.16
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
Wireshark Wireshark 0.9.10
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
Wireshark Wireshark 0.99
Mandriva lib64wireshark0-0.99.3a-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva libwireshark0-0.99.3a-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva tshark-0.99.3a-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva tshark-0.99.3a-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva wireshark-0.99.3a-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva wireshark-0.99.3a-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva wireshark-tools-0.99.3a-0.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Mandriva wireshark-tools-0.99.3a-0.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
Wireshark Wireshark 0.99.1
RedHat Fedora wireshark-0.99.3-fc5.1.i386.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-0.99.3-fc5.1.i386.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-0.99.3-fc5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-0.99.3-fc5.1.ppc.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-0.99.3-fc5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.i386.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.ppc.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.x86_64.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-gnome-0.99.3-fc5.1.i386.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-gnome-0.99.3-fc5.1.ppc.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-gnome-0.99.3-fc5.1.ppc.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-gnome-0.99.3-fc5.1.x86_64.rpm
Fedora Core 5
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
RedHat Fedora wireshark-gnome-0.99.3-fc5.1.x86_64.rpm
Fedora Core 5:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
Wireshark Wireshark 0.99.2
Wireshark wireshark-setup-0.99.3.exe
http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e
参考网址
来源: US-CERT
名称: VU#638376
链接:http://www.kb.cert.org/vuls/id/638376
来源: www.wireshark.org
链接:http://www.wireshark.org/security/wnpa-sec-2006-02.html
来源: BID
名称: 19690
链接:http://www.securityfocus.com/bid/19690
来源: VUPEN
名称: ADV-2006-3370
链接:http://www.frsirt.com/english/advisories/2006/3370
来源: SECTRACK
名称: 1016736
链接:http://securitytracker.com/id?1016736
来源: SECUNIA
名称: 21597
链接:http://secunia.com/advisories/21597
来源: XF
名称: wireshark-esp-offbyone(28553)
链接:http://xforce.iss.net/xforce/xfdb/28553
来源: REDHAT
名称: RHSA-2006:0658
链接:http://www.redhat.com/support/errata/RHSA-2006-0658.html
来源: MANDRIVA
名称: MDKSA-2006:152
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:152
来源: support.avaya.com
链接:http://support.avaya.com/elmodocs2/security/ASA-2006-227.htm
来源: GENTOO
名称: GLSA-200608-26
链接:http://security.gentoo.org/glsa/glsa-200608-26.xml
来源: SECUNIA
名称: 22378
链接:http://secunia.com/advisories/22378
来源: SECUNIA
名称: 21885
链接:http://secunia.com/advisories/21885
来源: SECUNIA
名称: 21682
链接:http://secunia.com/advisories/21682
来源: SECUNIA
名称: 21649
链接:http://secunia.com/advisories/21649
来源: SECUNIA
名称: 21619
链接:http://secunia.com/advisories/21619
来源: MANDRIVA
名称: MDKSA-2006:152
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:152