Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora: 2003-040 High Severity: Ethereal Malformed Packet Crashes

fedora
Calendar Grey December 19, 2003
Dist Fedora Esm H88
Ethereal application faces critical issues from malformed packets, an upgrade is vital to mitigate crashes and risks.
Both vulnerabilities will make the Ethereal application crash

Summary

This package lays base for libpcap, a packet capture and filtering

library, contains command-line utilities, contains plugins and

documentation for ethereal. A graphical user interface is packaged

separately to GTK+ package.

Update Information:

Serious issues have been discovered in the following protocol dissectors:

* Selecting "Match->Selected" or "Prepare->Selected" for a malformed SMB packet could cause a segmentation fault. * It is possible for the Q.931 dissector to dereference a null pointer when reading a malformed packet.

Impact:

Both vulnerabilities will make the Ethereal application crash. The Q.931 vulnerability also affects Tethereal. It is not known if either vulnerability can be used to make Ethereal or Tethereal run arbitrary code.

Resolution:

Upgrade to 0.10.0.

If you are running a version prior to 0.10.0 and you cannot upgrade, you can disable the SMB and Q.931 protocol dissectors by selecting Edit->Protocols... and deselecting them from the list. * Wed Dec 17 2003 Phil Knirsch <pknirsch@redhat.com> 0.10.0a-0.1

- Update to latest upstream version 0.10.0a - Fixed plugins problem.


This update can be downloaded from:


5ac28be19cc9b3113b6c339aed1c5f33 SRPMS/ethereal-0.10.0a-0.1.src.rpm...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2003-040 2003-12-18
Name : ethereal Version : 0.10.0a Release : 0.1 Summary : Network traffic analyzer Description : Ethereal is a network traffic analyzer for Unix-ish operating systems.
This package lays base for libpcap, a packet capture and filtering library, contains command-line utilities, contains plugins and documentation for ethereal. A graphical user interface is packaged separately to GTK+ package.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ethereal
Version: 0.10.0a
Release: 0.1
Summary: Network traffic analyzer

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here