Ethereal Multiple Protocol Dissector Vulnerabilities
BID:10347
Info
Ethereal Multiple Protocol Dissector Vulnerabilities
| Bugtraq ID: | 10347 |
| Class: | Unknown |
| CVE: |
CVE-2004-0504 CVE-2004-0505 CVE-2004-0506 CVE-2004-0507 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2004 12:00AM |
| Updated: | Jul 12 2009 04:07AM |
| Credit: | These issues were disclosed by the vendor. Discovery of one of the denial of service issues is credited to Martin Regner as well. |
| Vulnerable: |
SGI ProPack 3.0 SGI ProPack 2.4 Ethereal Group Ethereal 0.10.3 Ethereal Group Ethereal 0.10.2 Ethereal Group Ethereal 0.10.1 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.10.4 |
Discussion
Ethereal Multiple Protocol Dissector Vulnerabilities
It has been reported that Ethereal is prone to multiple vulnerabilities in various protocol dissectors. These issues can allow a remote attacker to carry out denial of service attacks and possibly exploit a buffer overflow vulnerability.
The denial of service issues are reported to affect Ethereal version 0.10.3 and the buffer overflow condition affects Ethereal 0.10.1 to 0.10.3.
These issues may be exploited during a live capture or when a malicious trace file is loaded.
Due to a lack of information, further details are not currently available. This BID will be updated as more information becomes available.
It has been reported that Ethereal is prone to multiple vulnerabilities in various protocol dissectors. These issues can allow a remote attacker to carry out denial of service attacks and possibly exploit a buffer overflow vulnerability.
The denial of service issues are reported to affect Ethereal version 0.10.3 and the buffer overflow condition affects Ethereal 0.10.1 to 0.10.3.
These issues may be exploited during a live capture or when a malicious trace file is loaded.
Due to a lack of information, further details are not currently available. This BID will be updated as more information becomes available.
Exploit / POC
Ethereal Multiple Protocol Dissector Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ethereal Multiple Protocol Dissector Vulnerabilities
Solution:
Conectiva has released advisory CLA-2005:916 along with fixes dealing with these and other issues. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200406-01 dealing with this issue. All Ethereal users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-analyzer/ethereal-0.10.4"
# emerge ">=net-analyzer/ethereal-0.10.4"
Please see the referenced Gentoo Linux advisory for more information.
The vendor has released version 0.10.4 to address these issues.
RedHat has released an advisory (RHSA-2004:234-06) to address these issues in RedHat Enterprise solutions. Please see the advisory in web references for more information.
Redhat has released advisories for Fedora Core 1 (FEDORA-2004-152) and Fedora Core 2 (FEDORA-2004-172) addressing these issues. Please see the referenced advisories for further information.
SGI has released a security advisory (20040604-01-U) to address this and other issues in SGI ProPack 3. Please see the referenced advisory for more information.
SGI has released a security advisory (20040605-01-U) to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information.
RedHat has released a Fedora legacy advisory (FLSA:1840) to address various issues in Ethereal. This advisory fixes these issues in Red Hat Linux 7.3 and 9 running on the i386 architecture. Please see the referenced advisory for more details and information about obtaining fixes.
SuSE Linux has made an advisory (SUSE-SR:2004:002) available. Please see the reference section for more information.
Ethereal Group Ethereal 0.10.1
Ethereal Group Ethereal 0.10.2
Ethereal Group Ethereal 0.10.3
SGI ProPack 2.4
SGI ProPack 3.0
Solution:
Conectiva has released advisory CLA-2005:916 along with fixes dealing with these and other issues. Please see the referenced advisory for more information.
Gentoo Linux has released advisory GLSA 200406-01 dealing with this issue. All Ethereal users should upgrade to the latest stable version:
# emerge sync
# emerge -pv ">=net-analyzer/ethereal-0.10.4"
# emerge ">=net-analyzer/ethereal-0.10.4"
Please see the referenced Gentoo Linux advisory for more information.
The vendor has released version 0.10.4 to address these issues.
RedHat has released an advisory (RHSA-2004:234-06) to address these issues in RedHat Enterprise solutions. Please see the advisory in web references for more information.
Redhat has released advisories for Fedora Core 1 (FEDORA-2004-152) and Fedora Core 2 (FEDORA-2004-172) addressing these issues. Please see the referenced advisories for further information.
SGI has released a security advisory (20040604-01-U) to address this and other issues in SGI ProPack 3. Please see the referenced advisory for more information.
SGI has released a security advisory (20040605-01-U) to address this and other issues in SGI ProPack 2.4. Please see the referenced advisory for more information.
RedHat has released a Fedora legacy advisory (FLSA:1840) to address various issues in Ethereal. This advisory fixes these issues in Red Hat Linux 7.3 and 9 running on the i386 architecture. Please see the referenced advisory for more details and information about obtaining fixes.
SuSE Linux has made an advisory (SUSE-SR:2004:002) available. Please see the reference section for more information.
Ethereal Group Ethereal 0.10.1
-
Ethereal Group Ethereal 0.10.4
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.10.2
-
Ethereal Group Ethereal 0.10.4
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.10.3
-
Ethereal Group Ethereal 0.10.4
http://www.ethereal.com/download.html -
RedHat ethereal-0.10.3-0.1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-0.10.3-0.1.1.i386.rpm -
RedHat ethereal-0.10.3-0.1.1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/ethereal-0.10.3-0.1.1.x86_64.rpm -
RedHat ethereal-0.10.3-0.73.3.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/ethereal-0.10 .3-0.73.3.legacy.i386.rpm -
RedHat ethereal-0.10.3-0.90.4.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/ethereal-0.10.3 -0.90.4.legacy.i386.rpm -
RedHat ethereal-0.10.3-2.2.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/i386 /ethereal-0.10.3-2.2.i386.rpm -
RedHat ethereal-0.10.3-2.2.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/x86_ 64/ethereal-0.10.3-2.2.x86_64.rpm -
RedHat ethereal-debuginfo-0.10.3-0.1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/ethereal-debuginfo-0.10.3-0.1.1.i386.rpm -
RedHat ethereal-debuginfo-0.10.3-0.1.1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/debug/ethereal-debuginfo-0.10.3-0.1.1.x86_64.rpm -
RedHat ethereal-debuginfo-0.10.3-2.2.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/i386 /debug/ethereal-debuginfo-0.10.3-2.2.i386.rpm -
RedHat ethereal-gnome-0.10.3-0.1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-gnome-0.10.3-0.1.1.i386.rpm -
RedHat ethereal-gnome-0.10.3-0.1.1.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/x86_ 64/ethereal-gnome-0.10.3-0.1.1.x86_64.rpm -
RedHat ethereal-gnome-0.10.3-0.73.3.legacy.i386.rpm
RedHat Linux 7.3
http://download.fedoralegacy.org/redhat/7.3/updates/i386/ethereal-gnom e-0.10.3-0.73.3.legacy.i386.rpm -
RedHat ethereal-gnome-0.10.3-0.90.4.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/ethereal-gnome- 0.10.3-0.90.4.legacy.i386.rpm -
RedHat ethereal-gnome-0.10.3-2.2.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/i386 /ethereal-gnome-0.10.3-2.2.i386.rpm -
RedHat ethereal-gnome-0.10.3-2.2.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/x86_ 64/ethereal-gnome-0.10.3-2.2.x86_64.rpm
SGI ProPack 2.4
-
SGI patch10084.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/2.4/patch1 0084.tar.gz
SGI ProPack 3.0
-
SGI patch10083.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/patch100 83.tar.gz
References
Ethereal Multiple Protocol Dissector Vulnerabilities
References:
References:
- Multiple security problems in Ethereal 0.10.3 (Ethereal Group)
- Re: [Ethereal-users] HotSIP sip-messages crasching ethereal (Ethereal Group)
- RHSA-2004:234-06 - Ethereal (RedHat)