GLSA: ethereal

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 08/30/02


From: Daniel Ahlberg <aliz@gentoo.org>
To: bugtraq@securityfocus.com
Date: Fri, 30 Aug 2002 10:22:44 +0200


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT
- - --------------------------------------------------------------------

PACKAGE :ethereal
SUMMARY :buffer overflow
DATE :2002-08-30 07:30 UTC

- - --------------------------------------------------------------------

OVERVIEW

The ISIS protocol dissector in Ethereal 0.9.5 and earlier versions
is susceptible to a buffer overflow.

DETAIL

It may be possible to make Ethereal crash or hang by injecting a
purposefully malformed packet onto the wire, or by convincing someone
to read a malformed packet trace file. It may be possible to make
Ethereal run arbitrary code by exploiting the buffer and pointer problems.

The full advisory can be read at
http://www.ethereal.com/appnotes/enpa-sa-00006.html

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-analyzer/ethereal-0.9.5-r2 and earlier update their systems
as follows:

emerge rsync
emerge ethereal
emerge clean

- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - --------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9bytUfT7nyhUpoZMRAms+AKCUt6lH8p4gYd+1D92rf3mod3YpuwCeJRSa
l4axUEqXgrW1U46/R5V8SN8=
=N0in
-----END PGP SIGNATURE-----



Relevant Pages

  • [Full-Disclosure] GLSA: krb5
    ... A stack buffer overflow in the implementation of the Kerberos v4 ... The attacker does not need to authenticate to the daemon to ... It is recommended that all Gentoo Linux users who are running ... emerge rsync ...
    (Full-Disclosure)
  • [Full-Disclosure] GLSA: ethereal
    ... is susceptible to a buffer overflow. ... purposefully malformed packet onto the wire, ... It is recommended that all Gentoo Linux users who are running ... emerge ethereal ...
    (Full-Disclosure)
  • GLSA: mod_php php
    ... GENTOO LINUX SECURITY ANNOUNCEMENT 200301-8 ... SUMMARY: buffer overflow ... Read the full advisory at ... emerge rsync ...
    (Bugtraq)
  • [Full-Disclosure] GLSA: pam_smb (200309-01)
    ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
    (Full-Disclosure)
  • [Full-Disclosure] GLSA: pam_smb (200309-01)
    ... "If a long password is supplied, this can cause a buffer overflow which ... It is recommended that all Gentoo Linux users who are running ... emerge pam_smb ... aliz@gentoo.org - GnuPG key is available at http://dev.gentoo.org/~aliz ...
    (Full-Disclosure)