oss-sec mailing list archives

Re: Wireshark - wnpa-sec-2009-05.html && wnpa-sec-2009-06.html -- CVE confirmation and CVE Request


From: Gerald Combs <gerald () wireshark org>
Date: Thu, 17 Sep 2009 16:59:13 -0700

Jan Lieskovsky wrote:
Hello Gerald, Steve, vendors,

  this is due:

    http://www.wireshark.org/security/wnpa-sec-2009-05.html
    http://www.wireshark.org/security/wnpa-sec-2009-06.html

  Gerald, could you please confirm, that:

    A, The AFS dissector could crash.   (Bug 3564)
       Versions affected: 0.9.2 to 1.0.8, 1.2.0

      is already assigned
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562 and

That's correct.


    B, The Infiniband dissector could crash on some platforms.
       Versions affected: 0.9.2 to 1.0.8, 1.2.0

       is already assigned
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563  ?

Correct.



Current thread: