Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· OCZ Vertex 450 Series Solid State Drives announced
· NVIDIA GeForce GTX 780 Reviews Roundup
· Apple's 'iWatch' to come in late 2014 with focus on biometrics, analyst says
· Windows 8.1 laptops with AMDs new chips to support wireless display
· HP $399 touchscreen laptop breaks price barrier
· What's Wrong with the Xbox One? and more
· Microsoft updates its YouTube Windows Phone app with some concessions to Google
· 3 Debian Updates
· The third screen: Will all Windows 8 apps run on Microsoft's Xbox One?
· CentOS-6.4 LiveCD and LiveDVD for i386 and x86_64 released

Upcoming News
· REVIEW: Nvidia GeForce GTX 780 @ PureOverclock
· iStarUSA BPU-340SATA Military Grade Drive Enclosure
· A Futurelooks New Flash - Futurelooks Weekly Giveawa?= y 2 of 3 – Win an ADATA XPG v1.0 1866mhz 8GB (4GB x 2) Mem?= ory Kit
· Security issue in livecd-tools causes password issue in Fedora cloud images
· Gigabyte C847N Motherboard @ Hardware Secrets
· An MTN News Flash - MEGATech Reviews – Tep Wireles?= s Pocket WiFi Mobile Hotspot Rental
· AMD Kabini Mainstream APU Notebook Platform Preview @ Legit Reviews
· OCZ Vertex 450 Solid State Drive Review
· [CentOS-announce] CEBA-2013:0858 CentOS 6 coreutils Update
· ZOTAC GeForce GTX 780 Graphics Card Video Review with Stuart Davidson @ HardwareHeaven.com

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6458 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 700 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4577 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 773 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1152 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2011 » OpenSSL/Wireshark Security Updates for Gentoo

OpenSSL/Wireshark Security Updates for Gentoo

Posted by Philipp Esselbach on: 10/10/2011 10:18 AM [ Print | 0 comment(s) ]

The following two security updates has been released for Gentoo: [ GLSA 201110-02 ] Wireshark: Multiple vulnerabilities and [ GLSA 201110-01 ] OpenSSL: Multiple vulnerabilities




[ GLSA 201110-02 ] Wireshark: Multiple vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201110-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Wireshark: Multiple vulnerabilities
Date: October 09, 2011
Bugs: #323859, #330479, #339401, #346191, #350551, #354197,
#357237, #363895, #369683, #373961, #381551, #383823, #386179
ID: 201110-02

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities in Wireshark allow for the remote execution of
arbitrary code, or a Denial of Service condition.

Background
==========

Wireshark is a versatile network protocol analyzer.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-analyzer/wireshark < 1.4.9 >= 1.4.9

Description
===========

Multiple vulnerabilities have been discovered in Wireshark. Please
review the CVE identifiers referenced below for details.

Impact
======

A remote attacker could send specially crafted packets on a network
being monitored by Wireshark, entice a user to open a malformed packet
trace file using Wireshark, or deploy a specially crafted Lua script
for use by Wireshark, possibly resulting in the execution of arbitrary
code, or a Denial of Service condition.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Wireshark users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/wireshark-1.4.9"

References
==========

[ 1 ] CVE-2010-2283
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2283
[ 2 ] CVE-2010-2284
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2284
[ 3 ] CVE-2010-2285
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2285
[ 4 ] CVE-2010-2286
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2286
[ 5 ] CVE-2010-2287
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2287
[ 6 ] CVE-2010-2992
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2992
[ 7 ] CVE-2010-2993
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2993
[ 8 ] CVE-2010-2994
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2994
[ 9 ] CVE-2010-2995
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2995
[ 10 ] CVE-2010-3133
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3133
[ 11 ] CVE-2010-3445
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3445
[ 12 ] CVE-2010-4300
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4300
[ 13 ] CVE-2010-4301
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4301
[ 14 ] CVE-2010-4538
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4538
[ 15 ] CVE-2011-0024
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0024
[ 16 ] CVE-2011-0444
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0444
[ 17 ] CVE-2011-0445
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0445
[ 18 ] CVE-2011-0538
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0538
[ 19 ] CVE-2011-0713
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0713
[ 20 ] CVE-2011-1138
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1138
[ 21 ] CVE-2011-1139
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1139
[ 22 ] CVE-2011-1140
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1140
[ 23 ] CVE-2011-1141
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1141
[ 24 ] CVE-2011-1142
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1142
[ 25 ] CVE-2011-1143
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1143
[ 26 ] CVE-2011-1590
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1590
[ 27 ] CVE-2011-1591
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1591
[ 28 ] CVE-2011-1592
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1592
[ 29 ] CVE-2011-1956
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1956
[ 30 ] CVE-2011-1957
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1957
[ 31 ] CVE-2011-1958
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1958
[ 32 ] CVE-2011-1959
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1959
[ 33 ] CVE-2011-2174
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2174
[ 34 ] CVE-2011-2175
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2175
[ 35 ] CVE-2011-2597
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2597
[ 36 ] CVE-2011-2698
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2698
[ 37 ] CVE-2011-3266
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3266
[ 38 ] CVE-2011-3360
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3360
[ 39 ] CVE-2011-3482
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3482
[ 40 ] CVE-2011-3483
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3483

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201110-02.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2011 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5



[ GLSA 201110-01 ] OpenSSL: Multiple vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201110-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: High
Title: OpenSSL: Multiple vulnerabilities
Date: October 09, 2011
Bugs: #303739, #308011, #322575, #332027, #345767, #347623,
#354139, #382069
ID: 201110-01

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities were found in OpenSSL, allowing for the
execution of arbitrary code and other attacks.

Background
==========

OpenSSL is an Open Source toolkit implementing the Secure Sockets Layer
(SSL v2/v3) and Transport Layer Security (TLS v1) as well as a general
purpose cryptography library.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-libs/openssl < 1.0.0e >= 1.0.0e

Description
===========

Multiple vulnerabilities have been discovered in OpenSSL. Please review
the CVE identifiers referenced below for details.

Impact
======

A context-dependent attacker could cause a Denial of Service, possibly
execute arbitrary code, bypass intended key requirements, force the
downgrade to unintended ciphers, bypass the need for knowledge of
shared secrets and successfully authenticate, bypass CRL validation, or
obtain sensitive information in applications that use OpenSSL.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All OpenSSL users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-1.0.0e"

NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since September 17, 2011. It is likely that your system is
already no longer affected by most of these issues.

References
==========

[ 1 ] CVE-2009-3245
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3245
[ 2 ] CVE-2009-4355
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4355
[ 3 ] CVE-2010-0433
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0433
[ 4 ] CVE-2010-0740
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0740
[ 5 ] CVE-2010-0742
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0742
[ 6 ] CVE-2010-1633
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1633
[ 7 ] CVE-2010-2939
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2939
[ 8 ] CVE-2010-3864
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3864
[ 9 ] CVE-2010-4180
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4180
[ 10 ] CVE-2010-4252
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4252
[ 11 ] CVE-2011-0014
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0014
[ 12 ] CVE-2011-3207
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3207
[ 13 ] CVE-2011-3210
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3210

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-201110-01.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2011 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5






Bookmark and Share

« Multiserver Setup With Dedicated Web, Email, DNS & MySQL Database Servers On Debian Squeeze With ISPConfig 3 · MySQL Tutorial: Install, Create DB and Table, Insert and Select Records »

Linux Compatible » News » October 2011 » OpenSSL/Wireshark Security Updates for Gentoo
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition