Upstream information

CVE-2009-3550 at MITRE

Description

The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.30
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entry: 550320 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP3 for x86
  • ethereal >= 0.10.14-16.39.1
sle10-sp3-sdk.x86
sles10-sp3.ppc
sle10-sp3-sdk.s390x
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.ppc
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sled10-sp3.x86-64
sled10-sp3.x86
sle10-sp3-sdk.x86-64
ZYPP Patch Nr: 6628
SUSE Linux Enterprise SDK 10 SP3
  • ethereal-devel >= 0.10.14-16.39.1
sle10-sp3-sdk.x86
sles10-sp3.ppc
sle10-sp3-sdk.s390x
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.ppc
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sled10-sp3.x86-64
sled10-sp3.x86
sle10-sp3-sdk.x86-64
ZYPP Patch Nr: 6628
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
  • ethereal >= 0.10.14-16.39.1
  • ethereal-devel >= 0.10.14-16.39.1
sle10-sp3-sdk.x86
sles10-sp3.ppc
sle10-sp3-sdk.s390x
sles10-sp3.x86
sles10-sp3.x86-64
sles10-sp3.ia64
sle10-sp3-sdk.ppc
sle10-sp3-sdk.ia64
sles10-sp3.s390x
sled10-sp3.x86-64
sled10-sp3.x86
sle10-sp3-sdk.x86-64
ZYPP Patch Nr: 6628
SUSE Linux Enterprise SDK 11 GA
  • wireshark >= 1.0.5-1.31.1
  • wireshark-devel >= 1.0.5-1.31.1
sles11.x86
sles11.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sle11-sdk.s390x
sles11.ia64
sles11.ppc
sle11-sdk.x86-64
sle11-sdk.ia64
sle11-debuginfo.ppc
sle11-debuginfo.s390x
sle11-debuginfo.x86
sled11.x86-64
sle11-debuginfo.ia64
sles11.s390x
sle11-debuginfo.x86-64
sled11.x86
SAT Patch Nr: 1606
SUSE Linux Enterprise SDK 11 GA
  • wireshark-devel >= 1.0.5-1.31.1
sles11.x86
sles11.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sle11-sdk.s390x
sles11.ia64
sles11.ppc
sle11-sdk.x86-64
sle11-sdk.ia64
sle11-debuginfo.ppc
sle11-debuginfo.s390x
sle11-debuginfo.x86
sled11.x86-64
sle11-debuginfo.ia64
sles11.s390x
sle11-debuginfo.x86-64
sled11.x86
SAT Patch Nr: 1606
SUSE Linux Enterprise Desktop 11 GA
SUSE Linux Enterprise Server 11 GA
  • wireshark >= 1.0.5-1.31.1
sles11.x86
sles11.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sle11-sdk.s390x
sles11.ia64
sles11.ppc
sle11-sdk.x86-64
sle11-sdk.ia64
sle11-debuginfo.ppc
sle11-debuginfo.s390x
sle11-debuginfo.x86
sled11.x86-64
sle11-debuginfo.ia64
sles11.s390x
sle11-debuginfo.x86-64
sled11.x86
SAT Patch Nr: 1606
Open Enterprise Server
  • ethereal >= 0.10.13-2.45
sles9-oes.x86
core9.x86
core9.x86-64
core9.ppc
core9.s390
sles9-nlpos.x86
core9.s390x
core9.ia64
YOU Patch Nr: 12530
openSUSE 11.0
  • wireshark-debuginfo >= 1.0.0-17.19
  • wireshark-debugsource >= 1.0.0-17.19
openSUSE 11.0
  • wireshark >= 1.0.0-17.19
  • wireshark-devel >= 1.0.0-17.19
openSUSE 11.1
  • wireshark-debuginfo >= 1.0.4-2.13.1
  • wireshark-debugsource >= 1.0.4-2.13.1
openSUSE 11.1
  • wireshark >= 1.0.4-2.13.1
  • wireshark-devel >= 1.0.4-2.13.1
openSUSE 11.2
  • wireshark-debuginfo >= 1.2.1-3.10.1
  • wireshark-debugsource >= 1.2.1-3.10.1
openSUSE 11.2
  • wireshark >= 1.2.1-3.10.1
  • wireshark-devel >= 1.2.1-3.10.1
SUSE Linux Enterprise SDK 10 SP2
  • ethereal-devel >= 0.10.14-16.40.1
sles10-sp2.x86
sles10-sp2.ia64
sle10-sp2-sdk.ia64
sles10-sp2.s390x
sle10-sp2-sdk.x86
sles10-sp2.ppc
sle10-sp2-sdk.s390x
sled10-sp2.x86
sle10-sp2-sdk.x86-64
sles10-sp2.x86-64
sled10-sp2.x86-64
sle10-sp2-sdk.ppc
ZYPP Patch Nr: 6627