Wireshark: Multiple vulnerabilities Multiple vulnerabilities have been discovered in Wireshark, allowing for the remote execution of arbitrary code, or Denial of Service. wireshark 2009-11-25 2009-11-25 285280 290710 remote 1.2.3 1.2.3

Wireshark is a versatile network protocol analyzer.

Multiple vulnerabilities have been discovered in Wireshark:

A remote attacker could entice a user to open a specially crafted "erf" file using Wireshark, possibly resulting in the execution of arbitrary code with the privileges of the user running the application. A remote attacker could furthermore send specially crafted packets on a network being monitored by Wireshark or entice a user to open a malformed packet trace file using Wireshark, possibly resulting in a Denial of Service.

There is no known workaround at this time.

All Wireshark users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-1.2.3"
CVE-2009-2560 CVE-2009-3241 CVE-2009-3242 CVE-2009-3243 CVE-2009-3549 CVE-2009-3550 CVE-2009-3551 CVE-2009-3829 a3li a3li a3li