Upstream information

CVE-2007-6439 at MITRE

Description

Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissector, which can trigger resource consumption or a crash. NOTE: this identifier originally included Firebird/Interbase, but it is already covered by CVE-2007-6116. The DCP ETSI issue is already covered by CVE-2007-6119.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.1
Vector AV:A/AC:L/Au:N/C:N/I:N/A:C
Access Vector Adjacent Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Complete
SUSE Bugzilla entry: 343574 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Novell Linux Desktop 9 SDK for x86
Novell Linux Desktop 9 SDK for x86_64
Open Enterprise Server
  • ethereal >= 0.10.13-2.30
sles10.x86
core9.x86
sles10.s390x
core9.x86
ZYPP Patch Nr: 4847
SUSE LINUX 10.1
  • ethereal >= 0.10.14-16.21
  • ethereal-devel >= 0.10.14-16.21
Builds