<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20836</bug_id>
          
          <creation_ts>2009-07-21 08:46:20 +0400</creation_ts>
          <short_desc>Multiple vulnerabilities in Wireshark:CVE-2009-2559, CVE-2009-2560, CVE-2009-2561, CVE-2009-2562, CVE-2009-2563</short_desc>
          <delta_ts>2010-01-29 12:17:41 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>wireshark-base</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.wireshark.org/security/wnpa-sec-2009-04.html</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Anton Farygin">rider</assigned_to>
          <cc>ldv</cc>
    
    <cc>rider</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>94981</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-07-21 08:46:20 +0400</bug_when>
    <thetext>Wireshark 1.2.1 fixes the following vulnerabilities:

    * The IPMI dissector could overrun a buffer. (Bug 3559) Versions affected: 1.2.0
    * The AFS dissector could crash. (Bug 3564) Versions affected: 0.9.2 to 1.2.0
    * The Infiniband dissector could crash on some platforms. Versions affected: 1.0.6 to 1.2.0
    * The Bluetooth L2CAP dissector could crash. (Bug 3572) Versions affected: 1.2.0
    * The RADIUS dissector could crash. (Bug 3578) Versions affected: 1.2.0
    * The MIOP dissector could crash. (Bug 3652) Versions affected: 1.2.0
    * The sFlow dissector could use excessive CPU and memory. (Bug 3570) Versions affected: 1.2.0</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>94984</commentid>
    <comment_count>1</comment_count>
    <who name="Alexander Bokovoy">ab</who>
    <bug_when>2009-07-21 09:46:53 +0400</bug_when>
    <thetext>Ok. Вечером.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96861</commentid>
    <comment_count>2</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2009-08-19 18:04:39 +0400</bug_when>
    <thetext>Вечером какого дня?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106090</commentid>
    <comment_count>3</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2010-01-28 15:11:37 +0300</bug_when>
    <thetext>Wireshark 1.2.6 is now available.

http://www.wireshark.org/security/wnpa-sec-2010-02.html
http://www.wireshark.org/security/wnpa-sec-2009-09.html
http://www.wireshark.org/security/wnpa-sec-2009-07.html
http://www.wireshark.org/security/wnpa-sec-2009-06.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106091</commentid>
    <comment_count>4</comment_count>
    <who name="Anton Farygin">rider</who>
    <bug_when>2010-01-28 15:13:15 +0300</bug_when>
    <thetext>Мне кажется, что пакету wireshark требуется другой мейнтейнер.

Саш, повесь его на @everybody или @nobody</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106100</commentid>
    <comment_count>5</comment_count>
    <who name="Alexander Bokovoy">ab</who>
    <bug_when>2010-01-28 17:21:58 +0300</bug_when>
    <thetext>ок, вечером.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106108</commentid>
    <comment_count>6</comment_count>
    <who name="Alexander Bokovoy">ab</who>
    <bug_when>2010-01-28 21:17:04 +0300</bug_when>
    <thetext>done</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106109</commentid>
    <comment_count>7</comment_count>
    <who name="Alexander Bokovoy">ab</who>
    <bug_when>2010-01-28 21:18:04 +0300</bug_when>
    <thetext>Перевожу на Антона.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106125</commentid>
    <comment_count>8</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-01-29 12:17:41 +0300</bug_when>
    <thetext>wireshark-1.2.6-alt1 -&gt; sisyphus:

* Thu Jan 28 2010 Anton Farygin &lt;rider@altlinux&gt; 1.2.6-alt1

- new version, multiple vulnerabilities fixed by upstream (closes #20836)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>