Wireshark DOCSIS Dissector DoS Vulnerability
Wireshark issued an update to fix an issue with the DOCSIS (Data Over Cable Service Interface Specification) dissector. It could be exploited by attackers to cause a DoS when processing malformed data, causing a crash of the application.
Affected Products
Wireshark versions 0.9.6 through 1.0.12 Bulletin can be viewed here.
Wireshark versions 1.2.0 through 1.2.7. Bulletin can be viewed here.
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot org
Microsoft Patch Tuesday May 2010 Pre-Release
Microsoft announced they will be releasing a total of 2 bulletins rated critical that could allow for remote code execution. The vulnerabilities affect Windows 2000, XP and Vista as well as Windows Server 2003, 2008 and 2008 R2. Other affected applications are Office XP, 2003, 2007 and MS Visual Basic. More details available here.
The recent SharePoint Security diary posted on ISC will not be addressed in the May bulletins.
[1] Microsoft Security Response Center Blog
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot org
Comments