Bug 559793 (CVE-2010-0304) - CVE-2010-0304 wireshark: crash in LWRES dissector
Summary: CVE-2010-0304 wireshark: crash in LWRES dissector
Alias: CVE-2010-0304
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 549581 549582 549583 549584 560743 561098 561099 833992
TreeView+ depends on / blocked
Reported: 2010-01-29 01:26 UTC by Vincent Danen
Modified: 2019-09-29 12:34 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2010-06-25 09:46:55 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0360 0 normal SHIPPED_LIVE Moderate: wireshark security update 2010-04-20 15:31:15 UTC

Description Vincent Danen 2010-01-29 01:26:31 UTC
Babi discovered several buffer overflows in the LWRES dissector which could be used to crash wireshark [1].

Fixed in trunk: r31524
Fixed in trunk-1.2: r31596
Fixed in trunk-1.0: r31671
Versions affected: 0.9.15 to 1.0.10, 1.2.0 to 1.2.5

[1] http://www.wireshark.org/security/wnpa-sec-2010-02.html

Comment 1 Vincent Danen 2010-01-30 05:21:04 UTC
This is CVE-2010-0304.

Comment 3 Vincent Danen 2010-02-01 18:54:45 UTC
The LWRES protocol is meant to be used locally to talk to BIND9 (for example, lwresd will only listen to


The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw. More information regarding issue severity can be found here:


Comment 8 Fedora Update System 2010-03-02 16:31:54 UTC
wireshark-1.2.6-1.fc12 has been submitted as an update for Fedora 12.

Comment 9 Fedora Update System 2010-03-04 00:09:23 UTC
wireshark-1.2.6-1.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 errata-xmlrpc 2010-04-20 15:31:28 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 4
  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 3

Via RHSA-2010:0360 https://rhn.redhat.com/errata/RHSA-2010-0360.html

Note You need to log in before you can comment on or make changes to this bug.