CVE-2008-0059
published 2008-03-18CVE-2008-0059: Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related…
medium5.8CVSS 3.1
AVNACMAuNCNIPAP
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-6450 wireshark RPL dissector crash
bugzilla·2008-01-02·CVSS 5.0
CVE-2007-6450 [MEDIUM] CVE-2007-6450 wireshark RPL dissector crash
CVE-2007-6450 wireshark RPL dissector crash
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6450 to the following vulnerability:
The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
References:
http://www.wireshark.org/security/wnpa-sec-2007-03.html
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
Bugzilla
CVE-2007-6451 wireshark CIP dissector crash
bugzilla·2008-01-02·CVSS 4.3
CVE-2007-6451 [MEDIUM] CVE-2007-6451 wireshark CIP dissector crash
CVE-2007-6451 wireshark CIP dissector crash
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6451 to the following vulnerability:
Unspecified vulnerability in the CIP dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger allocation of large amounts of memory.
References:
http://www.wireshark.org/security/wnpa-sec-2007-03.html
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
Bugzilla
CVE-2007-6121 wireshark RPC Portmap flaws
bugzilla·2007-11-23·CVSS 5.0
CVE-2007-6121 [MEDIUM] CVE-2007-6121 wireshark RPC Portmap flaws
CVE-2007-6121 wireshark RPC Portmap flaws
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6121 to the following vulnerability:
Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers
to cause a denial of service (crash) via a malformed RPC Portmap
packet.
Discussion:
wireshark-0.99.7-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-0.99.7-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
Fedora:
https://admin.fedoraproject.o
Bugzilla
CVE-2007-6117 wireshark HTTP dissector flaws
bugzilla·2007-11-23·CVSS 5.0
CVE-2007-6117 [MEDIUM] CVE-2007-6117 wireshark HTTP dissector flaws
CVE-2007-6117 wireshark HTTP dissector flaws
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6117 to the following vulnerability:
Unspecified vulnerability in the HTTP dissector for Wireshark
(formerly Ethereal) 0.10.14 to 0.99.6 has unknown impact and remote
attack vectors related to chunked messages.
Discussion:
wireshark-0.99.7-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-0.99.7-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
Fedo
Bugzilla
CVE-2007-6118 wireshark MEGACO dissector flaws
bugzilla·2007-11-23·CVSS 7.8
CVE-2007-6118 [HIGH] CVE-2007-6118 wireshark MEGACO dissector flaws
CVE-2007-6118 wireshark MEGACO dissector flaws
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6118 to the following vulnerability:
The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6
allows remote attackers to cause a denial of service (long loop and
resource consumption) via unknown vectors.
Discussion:
wireshark-0.99.7-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-0.99.7-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.
Bugzilla
CVE-2007-6120 wireshark Bluetooth SDP dissector flaws
bugzilla·2007-11-23·CVSS 5.0
CVE-2007-6120 [MEDIUM] CVE-2007-6120 wireshark Bluetooth SDP dissector flaws
CVE-2007-6120 wireshark Bluetooth SDP dissector flaws
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-6120 to the following vulnerability:
The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to
0.99.6 allows remote attackers to cause a denial of service (infinite
loop) via unknown vectors.
Discussion:
wireshark-0.99.7-2.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-0.99.7-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2008-0058.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
Fedo
Bugzilla
CVE-2007-3392 Wireshark crashes when inspecting MMS traffic
bugzilla·2007-06-29·CVSS 5.0
CVE-2007-3392 [MEDIUM] CVE-2007-3392 Wireshark crashes when inspecting MMS traffic
CVE-2007-3392 Wireshark crashes when inspecting MMS traffic
+++ This bug was initially created as a clone of Bug #246225 +++
Description of problem:
Wireshark was reported to crash due to NULL pointer dereference when
attempting to dissect a fuzzed MMS traffic traffic.
Version-Release number of selected component (if applicable):
Wireshark 0.99.5
Additional info:
This is fixed in upstream revision 20837.
I was not able to reproduce this on an x86_64 architecture box.
Discussion:
Created attachment 158202
Capture file of MMS traffic that crashes Wireshark
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0710.html
http://rhn.redhat.com/errata/RHSA-2007-0709.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
---
Reporter change
Bugzilla
CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic
bugzilla·2007-06-26·CVSS 5.0
CVE-2007-3392 [MEDIUM] CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic
CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic
Description of problem:
Wireshark enters an infinite loop when dissecting certain SSL traffic.
Version-Release number of selected component (if applicable):
Wireshark 0.99.5
Additional info:
No reproducer is available. This is fixed in upstream revision 21665.
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0710.html
http://rhn.redhat.com/errata/RHSA-2007-0709.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
---
Reporter changed to [email protected] by request of Jay Turner.
Bugzilla
CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic
bugzilla·2007-06-26·CVSS 5.0
CVE-2007-3389 [MEDIUM] CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic
CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic
Description of problem:
Wireshark crashes due to assertion fail when dissecting certain
HTTP traffic.
Version-Release number of selected component (if applicable):
Wireshark 0.99.5
Steps to Reproduce:
1. Open the attached capture with the Wireshark GUI
2. Click on the last HTTP packet
Additional info:
This is fixed in upstream revision 21034.
Discussion:
Created attachment 157935
Capture file of HTTP traffic that crashes Wireshark
---
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2007-0710.html
http://rhn.redhat.com/errata/RHSA-2007-0709.html
http://rhn.redhat.com/errata/RHSA-2008-0059.html
---
Reporter changed to [email protected] by request of Jay Turner.
http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/29420http://www.securityfocus.com/bid/28304http://www.securityfocus.com/bid/28367http://www.securitytracker.com/id?1019650http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41296http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://secunia.com/advisories/29420http://www.securityfocus.com/bid/28304http://www.securityfocus.com/bid/28367http://www.securitytracker.com/id?1019650http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41296
2008-03-18
Published