-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2014.1354
                         wireshark security update
                              11 August 2014

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           wireshark
Publisher:         Debian
Operating System:  Debian GNU/Linux 7
Impact/Access:     Denial of Service -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2014-5165 CVE-2014-5164 CVE-2014-5163
                   CVE-2014-5162 CVE-2014-5161 

Reference:         ASB-2014.0093

Original Bulletin: 
   http://www.debian.org/security/2014/dsa-3002

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-3002-1                   security@debian.org
http://www.debian.org/security/                        Moritz Muehlenhoff
August 10, 2014                        http://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : wireshark
CVE ID         : CVE-2014-5161 CVE-2014-5162 CVE-2014-5163 CVE-2014-5164 
                 CVE-2014-5165

Multiple vulnerabilities were discovered in the dissectors for Catapult 
DCT2000, IrDA, GSM Management, RLC ASN.1 BER, which could result in 
denial of service.

For the stable distribution (wheezy), these problems have been fixed in
version 1.8.2-5wheezy11.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your wireshark packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJT591HAAoJEBDCk7bDfE42E1sQALMpwQUN4Do9N93+x2IH9hXI
R09oZVFYyrBJRKR/Q8+Fs10paWYCrzZP98vrzkbrq8/uhlQh0cXjWrQ+5Ark3xmV
D87wZdYn5oUPL3pbK6ebMS+H9L5Q1zWfz+neLeUzxgZyNy5z6TdRNFEIiQaR0gQ7
b7CQp3qhmqW0xfYFFZn2vlx5WP7WZag0NyaB0P/MzUFWk2vB54QMo5hVqtpcTNPe
knp1h+izsdCD6955RF18Q6Z5Etw5qcWLwjCsbs97vdvvl/sO4sadh7UYJuW3FEDL
wtwEUXWI0BEMUxLGAalPo6GHikaYGZt2mnHRCZ+P10sEzVO4i3mPbdb+AAZa0cHZ
OCY5bFyrFTKrcAVdJ9LyqYqm9+cLFvxvpZ/t4cGkoFbhQxhy0c2ekWya2LQ+cVCs
5qLg2mjzLKJb+D9fYljXAn9txsxrvS8mG6LuEw4clRYFN3rD3xzi78qzl6qI4ccR
BenE9pv0wYLVzRo2pRVLLVXttZoGHd/CUSBcZrHyMTWZkJGTyUTdG6KkXZw4zKGo
n/6a5B78bxkGdYn3DRNnPeFbhJbKAMztiZ6bD9nhpDGlB6jfZmoCgQqH2BrEhj7I
SL5PlqjK4MoDMj+2wxGM9U5XAUNsUSxhqHSK1ugoqpTB72qFlv4gjqkRHD1m735w
U+lQM/z4dikyr6JXwZg4
=7RKp
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBU+g/NhLndAQH1ShLAQKhuw//TXvG1KVub+Fktio+Xk3ep93omXB9itrt
o5MLRDHDXo70GNVu27oa4fwCrK1Xbaabo4CJcZdmQs7QJ9iZwptR3MumoSuT6Pww
Z6e1s4dH2dygzq7JmifYenKh8trDk7Y86oazeITqi/JjvWXAC8bCxb4mge3Gukva
sLj77sZLG7FGvXrojABMjmj1wQk7OGDlOWb2S44M1h5ueu5ruhnHMJGy0uTRQpW+
FXxTDEAl9Y/Kpo8Z3Mzj9+3+p/i51XGRh/xJo+e585pSYAMtx9/OJB5UxdlY0U6H
ukY+5iNmvZriLBPETRIuM+wvEzqhhs7uoApV90Skmkw1VGA0lXQ5N/XnuHwCRbxg
k5/OjUVu47se4uBurjBoiLHhuiHF+z2QBQUkEHqB/lSnoj1ksKb6J83AUmXOq9Is
8XPG1RpL8+R0jXykuQOu+dM30fsCROG46Hbr+m9skwBMt23B+ZByQmWql/pTKezu
lsPFlm/O8FCEp/CZkEUfMrJEcrjuWftFB65wD5M3dSkQex+56oUPM7kB+Tsqr0t2
kyEskz151WeH7p7vsQBowU4ck6taf7yPsjEWjGtxKneaZttCAb9BXj8d+vAPpzG7
cCeWzjZYx4j6CGCjcuiEhsqaP5n4PhLAVZzsmi27MJRoZvMq5HNav3EC33BpLxYd
DZy67ke0OnM=
=gJ3A
-----END PGP SIGNATURE-----