Ethereal ASN.1 String Memory Allocation Denial Of Service Vulnerability
BID:4604
Info
Ethereal ASN.1 String Memory Allocation Denial Of Service Vulnerability
| Bugtraq ID: | 4604 |
| Class: | Design Error |
| CVE: |
CVE-2002-0353 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | This vulnerability announced by the Ethereal Development Team. |
| Vulnerable: |
Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 Ethereal Group Ethereal 0.8.18 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.9.3 |
Exploit / POC
Ethereal ASN.1 String Memory Allocation Denial Of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ethereal ASN.1 String Memory Allocation Denial Of Service Vulnerability
Solution:
Fixes available:
Ethereal Group Ethereal 0.8.18
Ethereal Group Ethereal 0.9.1
Ethereal Group Ethereal 0.9.2
Solution:
Fixes available:
Ethereal Group Ethereal 0.8.18
-
Red Hat ethereal-0.9.4-0.7.2.0.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/ethereal-0.9.4-0.7.2.0.i386.rp m -
Red Hat ethereal-0.9.4-0.7.2.0.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/ethereal-0.9.4-0.7.2.0.ia64.rp m -
Red Hat ethereal-gnome-0.9.4-0.7.2.0.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/ethereal-gnome-0.9.4-0.7.2.0.i 386.rpm -
Red Hat ethereal-gnome-0.9.4-0.7.2.0.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/ethereal-gnome-0.9.4-0.7.2.0.i a64.rpm
Ethereal Group Ethereal 0.9.1
-
Debian ethereal_0.8.0-3potato_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/ethe real_0.8.0-3potato_alpha.deb -
Debian ethereal_0.8.0-3potato_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/ethere al_0.8.0-3potato_arm.deb -
Debian ethereal_0.8.0-3potato_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/ether eal_0.8.0-3potato_i386.deb -
Debian ethereal_0.8.0-3potato_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/ether eal_0.8.0-3potato_m68k.deb -
Debian ethereal_0.8.0-3potato_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/et hereal_0.8.0-3potato_powerpc.deb -
Debian ethereal_0.8.0-3potato_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/ethe real_0.8.0-3potato_sparc.deb -
Ethereal Group ethereal-0.9.3.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.3.tar.gz
Ethereal Group Ethereal 0.9.2
-
Ethereal Group ethereal-0.9.3.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.3.tar.gz -
SCO ethereal-0.9.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2002-037.0/R PMS/ethereal-0.9.4-1.i386.rpm -
SCO ethereal-0.9.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2002-03 7.0/RPMS/ethereal-0.9.4-1.i386.rpm -
SCO ethereal-0.9.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Server/CSSA-2002-037.0/RPM S/ethereal-0.9.4-1.i386.rpm -
SCO ethereal-0.9.4-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1/Workstation/CSSA-2002-037. 0/RPMS/ethereal-0.9.4-1.i386.rpm
References
Ethereal ASN.1 String Memory Allocation Denial Of Service Vulnerability
References:
References:
- ASN.1 zero-length g_malloc (Ethereal)
- Feds, Industry, Battle the Biggest Bug (SecurityFocus)