oss-sec mailing list archives

Re: CVE requests: Poppler, Quassel, Pyfribidi, Overkill, DocUtils, FireGPG, Wireshark


From: Vincent Danen <vdanen () redhat com>
Date: Fri, 1 Oct 2010 14:12:37 -0600

* [2010-09-29 15:06:31 -0400] Josh Bressers wrote:

7. Wireshark BER dissector
http://archives.neohapsis.com/archives/bugtraq/2010-09/0088.html


This one looks like a stack overflow, the advisory isn't very clear, but
claims there are two possible outcomes. We can always split later if
needed.
CVE-2010-3445

Gerald, are you aware of this issue?  Do you have further details
regarding it?  I poked around in bugzilla a bit but couldn't find
anything.

It claims 1.4.0, but is not clear as to whether or not older versions
are affected.

--
Vincent Danen / Red Hat Security Response Team

Current thread: