Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
BID:13391
Info
Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
| Bugtraq ID: | 13391 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2005 12:00AM |
| Updated: | Apr 26 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Vade 79 <[email protected]>. |
| Vulnerable: |
Ethereal Group Ethereal 0.10.9 Ethereal Group Ethereal 0.10.8 Ethereal Group Ethereal 0.10.7 Ethereal Group Ethereal 0.10.6 Ethereal Group Ethereal 0.10.5 Ethereal Group Ethereal 0.10.4 Ethereal Group Ethereal 0.10.3 Ethereal Group Ethereal 0.10.2 Ethereal Group Ethereal 0.10.1 Ethereal Group Ethereal 0.10 .10 Ethereal Group Ethereal 0.10 Ethereal Group Ethereal 0.9.16 Ethereal Group Ethereal 0.9.15 Ethereal Group Ethereal 0.9.14 Ethereal Group Ethereal 0.9.13 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 Ethereal Group Ethereal 0.8.19 Ethereal Group Ethereal 0.8.18 Ethereal Group Ethereal 0.8.15 Ethereal Group Ethereal 0.8.14 Ethereal Group Ethereal 0.8.13 Ethereal Group Ethereal 0.8 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.10.11 |
Discussion
Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
Ethereal is prone to a vulnerability that may allow a remote attacker to cause a denial of service condition in the software. The issue occurs due to the way Ethereal decodes Resource ReSerVation Protocol (RSVP) packets. A remote attacker may cause the software to enter an infinite loop by sending malformed RSVP packets resulting in the software hanging.
Ethereal versions up to and including 0.10.10 are reported prone to this issue.
Ethereal is prone to a vulnerability that may allow a remote attacker to cause a denial of service condition in the software. The issue occurs due to the way Ethereal decodes Resource ReSerVation Protocol (RSVP) packets. A remote attacker may cause the software to enter an infinite loop by sending malformed RSVP packets resulting in the software hanging.
Ethereal versions up to and including 0.10.10 are reported prone to this issue.
Exploit / POC
Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue in Ethereal version 0.10.11.
Solution:
The vendor has addressed this issue in Ethereal version 0.10.11.
References
Ethereal RSVP Decoding Routines Denial Of Service Vulnerability
References:
References:
- Ethereal 0.10.11 released - Wednesday, May 4, 2005 (Ethereal Group)
- The Ethereal Network Analyzer (Ethereal Group)
- tcpdump(/ethereal)[]: (RSVP) rsvp_print() infinite loop DOS. (Vade 79
)