Wireshark-dev: Re: [Wireshark-dev] Segfault when running older Wireshark with capture from CVE-

From: Bálint Réczey <balint@xxxxxxxxxxxxxxx>
Date: Fri, 11 Nov 2016 12:33:54 +0100
2016-11-11 11:43 GMT+01:00 Guy Harris <guy@xxxxxxxxxxxx>:
> On Nov 11, 2016, at 1:59 AM, Anders Broman <anders.broman@xxxxxxxxxxxx> wrote:
>
>> https://wiki.wireshark.org/Development/LifeCycle
>>
>> Version  Stable Release Date  End of Life        Notes
>>
>> 1.8          June 21, 2012             June 21, 2014 Last release to support OS X on PPC
>>
>> 1.8 vent end-of-life June 21, 2014
>
> So the advice we have to offer is that you should either
>
>         1) update to a newer version of Wireshark that doesn't have the bug
>
> or
>
>         2) get the 1.8.x source, apply the fix yourself, recompile, and use that version

I maintain lts-* [1] branches mainly for organizing security patches
for Debian, but the
1.8 one is not active anymore. You may find fixes in those branches
which may be useful
for you in other cases.

Security releated patches are also welcome for the active branches which is only
lts-1.121 at the moment.

Cheers,
Balint

[1] https://code.wireshark.org/review/gitweb?p=wireshark.git;a=summary