-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-13416 2010-08-24 20:36:29 --------------------------------------------------------------------------------
Name : wireshark Product : Fedora 13 Version : 1.2.10 Release : 1.fc13 URL : http://www.wireshark.org/ Summary : Network traffic analyzer Description : Wireshark is a network traffic analyzer for Unix-ish operating systems. This package lays base for libpcap, a packet capture and filtering library, contains command-line utilities, contains plugins and documentation for wireshark. A graphical user interface is packaged separately to GTK+ package. -------------------------------------------------------------------------------- Update Information: Update to upstream version 1.2.10: * http://www.wireshark.org/docs/relnotes/wireshark-1.2.9.html * http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html fixing multiple security issues: * http://www.wireshark.org/security/wnpa-sec-2010-06.html * http://www.wireshark.org/security/wnpa-sec-2010-08.html -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 24 2010 Jan Safranek <[email protected]> - 1.2.10-1 - upgrade to 1.2.10 - see http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.html - Resolves: #625940 CVE-2010-2287 CVE-2010-2286 CVE-2010-2284 CVE-2010-2283 * Mon May 17 2010 Radek Vokal <[email protected]> - 1.2.8-3 - removing traling bracket from python_sitearch (#592391) * Fri May 7 2010 Radek Vokal <[email protected]> - 1.2.8-2 - add libtool patch * Fri May 7 2010 Radek Vokal <[email protected]> - 1.2.8-1 - use sitearch instead of sitelib to avoid pyo and pyc conflicts - upgrade to 1.2.8 - see http://www.wireshark.org/docs/relnotes/wireshark-1.2.8.html - rebuild with GeoIP support (needs to be turned on in IP protocol preferences) - bring back -pie -------------------------------------------------------------------------------- References: [ 1 ] Bug #604308 - CVE-2010-2287 CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns https://bugzilla.redhat.com/show_bug.cgi?id=604308 [ 2 ] Bug #604302 - CVE-2010-2286 wireshark: SigComp UDVM dissector infinite loop https://bugzilla.redhat.com/show_bug.cgi?id=604302 [ 3 ] Bug #604292 - CVE-2010-2284 wireshark: ASN.1 BER dissector stack overrun https://bugzilla.redhat.com/show_bug.cgi?id=604292 [ 4 ] Bug #604290 - CVE-2010-2283 wireshark: SMB dissector NULL pointer dereference https://bugzilla.redhat.com/show_bug.cgi?id=604290 [ 5 ] Bug #623843 - CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities https://bugzilla.redhat.com/show_bug.cgi?id=623843 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wireshark' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
