FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  372986
Date:      2014-11-21
Time:      11:06:59Z
Committer: madpilot

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
5415f1b3-f33d-11e1-8bd8-0022156e8794wireshark -- denial of service in DRDA dissector

RedHat security team reports:

A denial of service flaw was found in the way Distributed Relational Database Architecture (DRDA) dissector of Wireshark, a network traffic analyzer, performed processing of certain DRDA packet capture files. A remote attacker could create a specially-crafted capture file that, when opened could lead to wireshark executable to consume excessive amount of CPU time and hang with an infinite loop.


Discovery 2012-08-21
Entry 2012-08-31
Modified 2012-09-05
wireshark
ge 1.5 lt 1.9

wireshark-lite
ge 1.5 lt 1.9

tshark
ge 1.5 lt 1.9

tshark-lite
ge 1.5 lt 1.9

CVE-2012-3548
https://bugzilla.redhat.com/show_bug.cgi?id=849926
a7706414-1be7-11e2-9aad-902b343deec9Wireshark -- Multiple Vulnerabilities

Wireshark reports:

The HSRP dissector could go into an infinite loop.

The PPP dissector could abort.

Martin Wilck discovered an infinite loop in the DRDA dissector.

Laurent Butti discovered a buffer overflow in the LDP dissector.


Discovery 2012-10-02
Entry 2012-10-22
Modified 2013-06-19
wireshark
le 1.8.2_1

wireshark-lite
le 1.8.2_1

tshark
le 1.8.2_1

tshark-lite
le 1.8.2_1

CVE-2012-5237
CVE-2012-5238
CVE-2012-5239
CVE-2012-5240
http://www.wireshark.org/security/wnpa-sec-2012-26.html
http://www.wireshark.org/security/wnpa-sec-2012-27.html
http://www.wireshark.org/security/wnpa-sec-2012-28.html
http://www.wireshark.org/security/wnpa-sec-2012-29.html
http://www.wireshark.org/docs/relnotes/wireshark-1.8.3.html
4cdfe875-e8d6-11e1-bea0-002354ed89bcWireshark -- Multiple vulnerabilities

Wireshark reports:

It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

It may be possible to make Wireshark consume excessive CPU resources by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

The PPP dissector could crash.

The NFS dissector could use excessive amounts of CPU.

The DCP ETSI dissector could trigger a zero division.

The MongoDB dissector could go into a large loop.

The XTP dissector could go into an infinite loop.

The ERF dissector could overflow a buffer.

The AFP dissector could go into a large loop.

The RTPS2 dissector could overflow a buffer.

The GSM RLC MAC dissector could overflow a buffer.

The CIP dissector could exhaust system memory.

The STUN dissector could crash.

The EtherCAT Mailbox dissector could abort.

The CTDB dissector could go into a large loop.

The pcap-ng file parser could trigger a zero division.

The Ixia IxVeriWave file parser could overflow a buffer.


Discovery 2012-07-22
Entry 2012-08-18
wireshark
lt 1.8.2

wireshark-lite
lt 1.8.2

tshark
lt 1.8.2

tshark-lite
lt 1.8.2

CVE-2012-4048
CVE-2012-4049
CVE-2012-4285
CVE-2012-4286
CVE-2012-4287
CVE-2012-4288
CVE-2012-4289
CVE-2012-4290
CVE-2012-4291
CVE-2012-4292
CVE-2012-4293
CVE-2012-4294
CVE-2012-4295
CVE-2012-4296
CVE-2012-4297
CVE-2012-4298
http://www.wireshark.org/security/wnpa-sec-2012-11.html
http://www.wireshark.org/security/wnpa-sec-2012-12.html
http://www.wireshark.org/security/wnpa-sec-2012-13.html
http://www.wireshark.org/security/wnpa-sec-2012-14.html
http://www.wireshark.org/security/wnpa-sec-2012-15.html
http://www.wireshark.org/security/wnpa-sec-2012-16.html
http://www.wireshark.org/security/wnpa-sec-2012-17.html
http://www.wireshark.org/security/wnpa-sec-2012-18.html
http://www.wireshark.org/security/wnpa-sec-2012-19.html
http://www.wireshark.org/security/wnpa-sec-2012-20.html
http://www.wireshark.org/security/wnpa-sec-2012-21.html
http://www.wireshark.org/security/wnpa-sec-2012-22.html
http://www.wireshark.org/security/wnpa-sec-2012-23.html
http://www.wireshark.org/security/wnpa-sec-2012-24.html
http://www.wireshark.org/security/wnpa-sec-2012-25.html
5415f1b3-f33d-11e1-8bd8-0022156e8794wireshark -- denial of service in DRDA dissector

RedHat security team reports:

A denial of service flaw was found in the way Distributed Relational Database Architecture (DRDA) dissector of Wireshark, a network traffic analyzer, performed processing of certain DRDA packet capture files. A remote attacker could create a specially-crafted capture file that, when opened could lead to wireshark executable to consume excessive amount of CPU time and hang with an infinite loop.


Discovery 2012-08-21
Entry 2012-08-31
Modified 2012-09-05
wireshark
ge 1.5 lt 1.9

wireshark-lite
ge 1.5 lt 1.9

tshark
ge 1.5 lt 1.9

tshark-lite
ge 1.5 lt 1.9

CVE-2012-3548
https://bugzilla.redhat.com/show_bug.cgi?id=849926
5415f1b3-f33d-11e1-8bd8-0022156e8794wireshark -- denial of service in DRDA dissector

RedHat security team reports:

A denial of service flaw was found in the way Distributed Relational Database Architecture (DRDA) dissector of Wireshark, a network traffic analyzer, performed processing of certain DRDA packet capture files. A remote attacker could create a specially-crafted capture file that, when opened could lead to wireshark executable to consume excessive amount of CPU time and hang with an infinite loop.


Discovery 2012-08-21
Entry 2012-08-31
Modified 2012-09-05
wireshark
ge 1.5 lt 1.9

wireshark-lite
ge 1.5 lt 1.9

tshark
ge 1.5 lt 1.9

tshark-lite
ge 1.5 lt 1.9

CVE-2012-3548
https://bugzilla.redhat.com/show_bug.cgi?id=849926