CVE-2007-6114
wireshark - several vulnerabilities
EPSS 6.3%
描述
Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) the SSL dissector or (2) the iSeries (OS/400) Communication trace file parser.
如何修補 CVE-2007-6114
要修補 CVE-2007-6114,請將受影響套件升級到下列已修補版本。
- Debian/ethereal—升級至 0.10.10-2sarge10 或更新版本
- Debian/wireshark—升級至 0.99.7~pre1-1 或更新版本
- Debian/wireshark—升級至 0.99.4-5.etch.1 或更新版本
CVE-2007-6114 正在被利用嗎?
中等 — EPSS 為 6.3%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 0.10.10-2sarge10
- from 0, < 0.99.7~pre1-1
- from 0, < 0.99.4-5.etch.1