Bug 468175 (CVE-2008-4685) - CVE-2008-4685 wireshark: DoS (app crash or abort) in Q.931 dissector via certain packets
Summary: CVE-2008-4685 wireshark: DoS (app crash or abort) in Q.931 dissector via cert...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2008-4685
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 486548 486549 486550 486551 486552 833990
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-10-23 13:11 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:26 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-03-05 07:48:29 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2009:0313 0 normal SHIPPED_LIVE Moderate: wireshark security update 2009-03-04 19:41:33 UTC

Description Jan Lieskovsky 2008-10-23 13:11:35 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4685 to
the following vulnerability:

Use-after-free vulnerability in the dissect_q931_cause_ie function in
packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3
allows remote attackers to cause a denial of service (application
crash or abort) via certain packets that trigger an exception.

Affected Wireshark versions: 0.10.3 through 1.0.3

References: 

http://www.wireshark.org/security/wnpa-sec-2008-06.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2870
http://www.securityfocus.com/bid/31838
http://www.frsirt.com/english/advisories/2008/2872
http://securitytracker.com/id?1021069
http://secunia.com/advisories/32355

Comment 4 Red Hat Product Security 2009-03-05 07:48:29 UTC
This issue was addressed in:

Red Hat Enterprise Linux:
  http://rhn.redhat.com/errata/RHSA-2009-0313.html


Note You need to log in before you can comment on or make changes to this bug.