Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Gentoo 200311-04 Normal: Ethereal Multi-Exploit Remote Code Risk

gentoo
Calendar Grey November 24, 2003
Dist Gentoo Esm H88
Critical security vulnerabilities in the Ethereal package on Gentoo Linux could allow remote code execution. Immediate patching and system monitoring are essential to safeguard infrastructures
It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packe...

Summary


----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200311-04 - - ---------------------------------------------------------------------------
GLSA: 200311-04 package: net-analyzer/ethereal summary: Security problems in Ethereal 0.9.15 severity: normal Gentoo bug: 32691 date: 2003-11-22 CVE: none exploit: remote affected: <0.9.16 fixed:>=0.9.16
DESCRIPTION:

Quote from <
Potential security issues have been discovered in the following protocol dissectors:
* An improperly formatted GTP MSISDN string could cause a buffer overflow.
* A malformed ISAKMP or MEGACO packet could make Ethereal or Tethereal crash.
* The SOCKS dissector was susceptible to a heap overlfow.
Impact:
It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
medium
Lowest
Low
Medium
High
Critical


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3269669_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here