Wireshark IPSec ESP解析器缓冲区溢出漏洞

漏洞信息详情

Wireshark IPSec ESP解析器缓冲区溢出漏洞

漏洞简介

Wireshark是一款非常流行的网络协议分析工具,以前名为Ethereal。

Wireshark中存在多个安全漏洞,具体如下:

如果编译了ESP解密支持的话,IPSec ESP选择解析器中就会存在单字节缓冲区溢出漏洞;

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Wireshark Wireshark 0.7.9

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

Wireshark Wireshark 0.8.16

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

Wireshark Wireshark 0.9.10

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

Wireshark Wireshark 0.99

Mandriva lib64wireshark0-0.99.3a-0.1.20060mdk.x86_64.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva libwireshark0-0.99.3a-0.1.20060mdk.i586.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva tshark-0.99.3a-0.1.20060mdk.i586.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva tshark-0.99.3a-0.1.20060mdk.x86_64.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva wireshark-0.99.3a-0.1.20060mdk.i586.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva wireshark-0.99.3a-0.1.20060mdk.x86_64.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva wireshark-tools-0.99.3a-0.1.20060mdk.i586.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Mandriva wireshark-tools-0.99.3a-0.1.20060mdk.x86_64.rpm

Mandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

Wireshark Wireshark 0.99.1

RedHat Fedora wireshark-0.99.3-fc5.1.i386.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-0.99.3-fc5.1.i386.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-0.99.3-fc5.1.ppc.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-0.99.3-fc5.1.ppc.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-0.99.3-fc5.1.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.i386.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.ppc.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.ppc.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-debuginfo-0.99.3-fc5.1.x86_64.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-gnome-0.99.3-fc5.1.i386.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-gnome-0.99.3-fc5.1.ppc.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-gnome-0.99.3-fc5.1.ppc.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-gnome-0.99.3-fc5.1.x86_64.rpm

Fedora Core 5

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

RedHat Fedora wireshark-gnome-0.99.3-fc5.1.x86_64.rpm

Fedora Core 5:

http://download.fedora.redhat.com/pub/fedora/linux/core/updates/5/

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

Wireshark Wireshark 0.99.2

Wireshark wireshark-setup-0.99.3.exe

http://prdownloads.sourceforge.net/wireshark/wireshark-setup-0.99.3.ex e

参考网址

来源: US-CERT

名称: VU#638376

链接:http://www.kb.cert.org/vuls/id/638376

来源: www.wireshark.org

链接:http://www.wireshark.org/security/wnpa-sec-2006-02.html

来源: BID

名称: 19690

链接:http://www.securityfocus.com/bid/19690

来源: VUPEN

名称: ADV-2006-3370

链接:http://www.frsirt.com/english/advisories/2006/3370

来源: SECTRACK

名称: 1016736

链接:http://securitytracker.com/id?1016736

来源: SECUNIA

名称: 21597

链接:http://secunia.com/advisories/21597

来源: XF

名称: wireshark-esp-offbyone(28553)

链接:http://xforce.iss.net/xforce/xfdb/28553

来源: REDHAT

名称: RHSA-2006:0658

链接:http://www.redhat.com/support/errata/RHSA-2006-0658.html

来源: MANDRIVA

名称: MDKSA-2006:152

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:152

来源: support.avaya.com

链接:http://support.avaya.com/elmodocs2/security/ASA-2006-227.htm

来源: GENTOO

名称: GLSA-200608-26

链接:http://security.gentoo.org/glsa/glsa-200608-26.xml

来源: SECUNIA

名称: 22378

链接:http://secunia.com/advisories/22378

来源: SECUNIA

名称: 21885

链接:http://secunia.com/advisories/21885

来源: SECUNIA

名称: 21682

链接:http://secunia.com/advisories/21682

来源: SECUNIA

名称: 21649

链接:http://secunia.com/advisories/21649

来源: SECUNIA

名称: 21619

链接:http://secunia.com/advisories/21619

来源: MANDRIVA

名称: MDKSA-2006:152

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:152

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享