Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
BID:12759
Info
Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
| Bugtraq ID: | 12759 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0699 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2005 12:00AM |
| Updated: | Jul 31 2006 11:56PM |
| Credit: | Both Leon Juranic and Diego Giagio <[email protected]> independently discovery this issue. |
| Vulnerable: |
Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Ethereal Group Ethereal 0.10.9 Ethereal Group Ethereal 0.10.8 Ethereal Group Ethereal 0.10.7 Ethereal Group Ethereal 0.10.6 Ethereal Group Ethereal 0.10.5 Ethereal Group Ethereal 0.10.4 Ethereal Group Ethereal 0.10.3 Ethereal Group Ethereal 0.10.2 Ethereal Group Ethereal 0.10.1 Ethereal Group Ethereal 0.10 Avaya S8710 R2.0.1 Avaya S8710 R2.0.0 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Converged Communications Server 2.0 ALT Linux ALT Linux Junior 2.3 ALT Linux ALT Linux Compact 2.3 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.10 .10 |
Discussion
Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
A remote buffer-overflow vulnerability reportedly affects Ethereal because it fails to securely copy network-derived data into sensitive process buffers. The specific issue resides in the 3GPP2 A11 dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote buffer-overflow vulnerability reportedly affects Ethereal because it fails to securely copy network-derived data into sensitive process buffers. The specific issue resides in the 3GPP2 A11 dissector.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
Solution:
Please see the references for more information.
Ethereal Group Ethereal 0.10
Ethereal Group Ethereal 0.10.1
Ethereal Group Ethereal 0.10.2
Ethereal Group Ethereal 0.10.3
Ethereal Group Ethereal 0.10.4
Ethereal Group Ethereal 0.10.5
Ethereal Group Ethereal 0.10.6
Ethereal Group Ethereal 0.10.7
Ethereal Group Ethereal 0.10.8
Ethereal Group Ethereal 0.10.9
Solution:
Please see the references for more information.
Ethereal Group Ethereal 0.10
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.1
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.2
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.3
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe -
Fedora ethereal-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora ethereal-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora ethereal-debuginfo-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora ethereal-debuginfo-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora ethereal-gnome-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora ethereal-gnome-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora Legacy ethereal-0.10.13-1.FC2.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/ethereal-0.10.1 3-1.FC2.2.legacy.i386.rpm -
Fedora Legacy ethereal-gnome-0.10.13-1.FC2.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/ethereal-gnome- 0.10.13-1.FC2.2.legacy.i386.rpm -
Mandrake ethereal-0.10.10-0.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ethereal-0.10.10-0.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Ethereal Group Ethereal 0.10.4
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.5
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.6
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe -
Fedora ethereal-0.10.10-1.FC3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora ethereal-0.10.10-1.FC3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora ethereal-debuginfo-0.10.10-1.FC3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora ethereal-debuginfo-0.10.10-1.FC3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora ethereal-gnome-0.10.10-1.FC3.1.i386.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Fedora ethereal-gnome-0.10.10-1.FC3.1.x86_64.rpm
RedHat Fedora Core 3
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/ -
Mandrake ethereal-0.10.10-0.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ethereal-0.10.10-0.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ethereal-tools-0.10.10-0.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake ethereal-tools-0.10.10-0.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64ethereal0-0.10.10-0.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libethereal0-0.10.10-0.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake tethereal-0.10.10-0.1.101mdk.i586.rpm
Mandrake Linux 10.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake tethereal-0.10.10-0.1.101mdk.x86_64.rpm
Mandrake Linux 10.1/x86_64
http://www.mandrakesecure.net/en/ftp.php
Ethereal Group Ethereal 0.10.7
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.8
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.9
-
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html -
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz -
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
References
Ethereal RADIUS Authentication Dissection Buffer Overflow Vulnerability
References:
References:
- [security-announce] I: updated packages available (ALT Linux)
- ASA-2005-131 - Ethereal (Avaya)
- enpa-sa-00018 Multiple problems in Ethereal versions 0.9.1 to 0.10.9 (Ethereal Group)
- RHSA-2005:306-10 - ethereal security update (RedHat)
- The Ethereal Network Analyzer (Ethereal Group)
- Ethereal remote buffer overflow (LSS Security
) - Re: Ethereal remote buffer overflow ( Gerald Combs
) - Re: Ethereal remote buffer overflow (Diego Giagio
) - RE: Ethereal remote buffer overflow - addon (LSS Security
)