Debian Security Advisory

DSA-2700-1 wireshark -- several vulnerabilities

Date Reported:
02 Jun 2013
Affected Packages:
wireshark
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-3555, CVE-2013-3557, CVE-2013-3558, CVE-2013-3559, CVE-2013-3560, CVE-2013-3562.
More information:

Multiple vulnerabilities were discovered in the dissectors for GTPv2, ASN.1 BER, PPP CCP, DCP ETSI, MPEG DSM-CC and Websocket, which could result in denial of service or the execution of arbitrary code.

The oldstable distribution (squeeze) is not affected.

For the stable distribution (wheezy), these problems have been fixed in version 1.8.2-5wheezy3.

For the unstable distribution (sid), these problems have been fixed in version 1.8.7-1.

We recommend that you upgrade your wireshark packages.