Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3146 to the following vulnerability: Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used. References: http://www.wireshark.org/security/wnpa-sec-2008-05.html http://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2675 http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html
wireshark-1.0.3-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
wireshark-1.0.3-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
This issue was addressed in: Red Hat Enterprise Linux: http://rhn.redhat.com/errata/RHSA-2008-0890.html Fedora: https://admin.fedoraproject.org/updates/F8/FEDORA-2008-7894 https://admin.fedoraproject.org/updates/F9/FEDORA-2008-7936