An invalid pointer dereference flaw was found in the Wireshark's Paltalk dissector. A remote attacker could provide a specially-crafted Paltalk packet capture file, which once opened by an unsuspecting user would lead to denial of service (Wireshark crash). References: ----------- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689 http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-paltalk.c?view=log&pathrev=29064 Upstream patch: --------------- http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-paltalk.c?r1=28437&r2=29064&pathrev=29064&view=patch
This issue does NOT affect the versions of the wireshark package, as shipped with Red Hat Enterprise Linux 3, 4, or 5. This issue affects the versions of the wireshark package, as shipped with Fedora releases of 10, 11, and as scheduled to appear in Fedora release of 12.
1.2.3: http://www.wireshark.org/security/wnpa-sec-2009-07.html