Skip to main content

Wireshark updates fix security vulnerabilities

posted onJuly 20, 2011
by l33tdawg

The Wireshark developers have announced the release of versions 1.6.1 and 1.4.8 of their open source, cross-platform network protocol analyser. These maintenance and security updates address multiple vulnerabilities that could cause Wireshark to crash "by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file."

These include problems related to the Lucent/Ascend file parser and the ANSI MAP dissector, both of which were susceptible to an infinite loop bug. Wireshark 1.4.0 to 1.4.7 and 1.6.0 are said to be affected. A number of bugs in both versions were also fixed. All users are advised to update to the latest versions.

Version 1.2.18 of Wireshark from the end of June addressed the same vulnerabilities noted above; the 1.2.x branch reached its end of life on 30 June 2011. All Wireshark 1.2.x users are encouraged to upgrade to the 1.6.x branch.

Source

Tags

Software-Programming

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th