OpenSSL/Wireshark Security Updates for Gentoo
Posted on: 10/10/2011 12:18 PM

The following two security updates has been released for Gentoo: [ GLSA 201110-02 ] Wireshark: Multiple vulnerabilities and [ GLSA 201110-01 ] OpenSSL: Multiple vulnerabilities

[ GLSA 201110-02 ] Wireshark: Multiple vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201110-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Wireshark: Multiple vulnerabilities
Date: October 09, 2011
Bugs: #323859, #330479, #339401, #346191, #350551, #354197,
#357237, #363895, #369683, #373961, #381551, #383823, #386179
ID: 201110-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in Wireshark allow for the remote execution of
arbitrary code, or a Denial of Service condition.

Background
==========

Wireshark is a versatile network protocol analyzer.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-analyzer/wireshark < 1.4.9 >= 1.4.9

Description
===========

Multiple vulnerabilities have been discovered in Wireshark. Please
review the CVE identifiers referenced below for details.

Impact
======

A remote attacker could send specially crafted packets on a network
being monitored by Wireshark, entice a user to open a malformed packet
trace file using Wireshark, or deploy a specially crafted Lua script
for use by Wireshark, possibly resulting in the execution of arbitrary
code, or a Denial of Service condition.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Wireshark users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-1.4.9"

References
==========

[ 1 ] CVE-2010-2283
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2283
[ 2 ] CVE-2010-2284
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2284
[ 3 ] CVE-2010-2285
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2285
[ 4 ] CVE-2010-2286
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2286
[ 5 ] CVE-2010-2287
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2287
[ 6 ] CVE-2010-2992
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2992
[ 7 ] CVE-2010-2993
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2993
[ 8 ] CVE-2010-2994
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2994
[ 9 ] CVE-2010-2995
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2995
[ 10 ] CVE-2010-3133
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3133
[ 11 ] CVE-2010-3445
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3445
[ 12 ] CVE-2010-4300
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4300
[ 13 ] CVE-2010-4301
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4301
[ 14 ] CVE-2010-4538
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4538
[ 15 ] CVE-2011-0024
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0024
[ 16 ] CVE-2011-0444
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0444
[ 17 ] CVE-2011-0445
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0445
[ 18 ] CVE-2011-0538
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0538
[ 19 ] CVE-2011-0713
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0713
[ 20 ] CVE-2011-1138
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1138
[ 21 ] CVE-2011-1139
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1139
[ 22 ] CVE-2011-1140
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1140
[ 23 ] CVE-2011-1141
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1141
[ 24 ] CVE-2011-1142
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1142
[ 25 ] CVE-2011-1143
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1143
[ 26 ] CVE-2011-1590
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1590
[ 27 ] CVE-2011-1591
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1591
[ 28 ] CVE-2011-1592
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1592
[ 29 ] CVE-2011-1956
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1956
[ 30 ] CVE-2011-1957
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1957
[ 31 ] CVE-2011-1958
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1958
[ 32 ] CVE-2011-1959
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1959
[ 33 ] CVE-2011-2174
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2174
[ 34 ] CVE-2011-2175
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2175
[ 35 ] CVE-2011-2597
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2597
[ 36 ] CVE-2011-2698
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2698
[ 37 ] CVE-2011-3266
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3266
[ 38 ] CVE-2011-3360
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3360
[ 39 ] CVE-2011-3482
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3482
[ 40 ] CVE-2011-3483
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3483

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201110-02.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2011 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5



[ GLSA 201110-01 ] OpenSSL: Multiple vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201110-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: OpenSSL: Multiple vulnerabilities
Date: October 09, 2011
Bugs: #303739, #308011, #322575, #332027, #345767, #347623,
#354139, #382069
ID: 201110-01

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities were found in OpenSSL, allowing for the
execution of arbitrary code and other attacks.

Background
==========

OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
(SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
purpose cryptography library.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-libs/openssl < 1.0.0e >= 1.0.0e

Description
===========

Multiple vulnerabilities have been discovered in OpenSSL. Please review
the CVE identifiers referenced below for details.

Impact
======

A context-dependent attacker could cause a Denial of Service, possibly
execute arbitrary code, bypass intended key requirements, force the
downgrade to unintended ciphers, bypass the need for knowledge of
shared secrets and successfully authenticate, bypass CRL validation, or
obtain sensitive information in applications that use OpenSSL.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All OpenSSL users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.0e"

NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since September 17, 2011. It is likely that your system is
already no longer affected by most of these issues.

References
==========

[ 1 ] CVE-2009-3245
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3245
[ 2 ] CVE-2009-4355
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4355
[ 3 ] CVE-2010-0433
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0433
[ 4 ] CVE-2010-0740
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0740
[ 5 ] CVE-2010-0742
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0742
[ 6 ] CVE-2010-1633
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1633
[ 7 ] CVE-2010-2939
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2939
[ 8 ] CVE-2010-3864
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3864
[ 9 ] CVE-2010-4180
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4180
[ 10 ] CVE-2010-4252
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4252
[ 11 ] CVE-2011-0014
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0014
[ 12 ] CVE-2011-3207
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3207
[ 13 ] CVE-2011-3210
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3210

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201110-01.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2011 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5







Printed from Linux Compatible (http://www.linuxcompatible.org/news/story/opensslwireshark_security_updates_for_gentoo.html)