Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Debian: 407-1 Moderate Vulnerability in Ethereal Denial Of Service

debian
Calendar Grey January 5, 2004
Scroller Debian
A heap-based buffer overflow in Ethereal allows remote attackers to crash the system and possibly execute code.
A heap-based buffer overflow allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

Summary

Package : ethereal
Vulnerability : buffer overflows
Problem-Type : remote
Debian-specific: no
CVE IDs : CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013

Several vulnerabilities were discovered upstream in ethereal, a
network traffic analyzer. The Common Vulnerabilities and Exposures
project identifies the following problems:

CAN-2003-0925

A buffer overflow allows remote attackers to cause a denial of
service and possibly execute arbitrary code via a malformed GTP
MSISDN string.

CAN-2003-0926

Via certain malformed ISAKMP or MEGACO packets remote attackers are
able to cause a denial of service (crash).

CAN-2003-0927

A heap-based buffer overflow allows remote attackers to cause a
denial of service (crash) and possibly execute arbitrary code via
the SOCKS dissector.

CAN-2003-1012

The SMB dissector allows remote attackers to cause a denial of
service via a malformed SMB packet that triggers a segmentation
fault during processing of select...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: ethereal
CVE IDs: CAN-2003-0925 CAN-2003-0926 CAN-2003-0927 CAN-2003-1012 CAN-2003-1013

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.