Ethereal SPNEGO Dissector Denial Of Service Vulnerability
BID:7879
Info
Ethereal SPNEGO Dissector Denial Of Service Vulnerability
| Bugtraq ID: | 7879 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0430 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability credited to Timo Sirainen. |
| Vulnerable: |
SCO OpenLinux Workstation 3.1.1 SCO OpenLinux Server 3.1.1 Redhat Linux Advanced Work Station 2.1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.9.13 |
Exploit / POC
Ethereal SPNEGO Dissector Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ethereal SPNEGO Dissector Denial Of Service Vulnerability
Solution:
SCO have released an advisory (CSSA-2003-030.0) and fixes to address this issue. Affected users are advised to install the appropriate fix as soon as possible. Further information regarding the application of these fixes can be found in the referenced advisory. Fixes are linked below.
Conectiva has released a security advisory (CLSA-2003:719) and fixes to address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released a security advisory (RHSA-2003:077-13) containing fixes which address this and other issues with ethereal. See referenced advisory for further details on obtaining and applying fixes.
Conectiva has released a security advisory (CLA-2003:662) and fixes to address this issue. Users are advised to upgrade as soon as possible.
Ethereal 0.9.13 is not vulnerable to this issue. Affected users are advised to upgrade to the newest version of Ethereal.
Red Hat has released upgraded RPMs which correct this vulnerability. Please see advisory RHSA-2003:203-01 (references section) for download links.
Updates are available for Yellow Dog Linux. These updates can be applied manually or by issuing the following command:
yum update ethereal
Ethereal Group Ethereal 0.9
Ethereal Group Ethereal 0.9.1
Ethereal Group Ethereal 0.9.10
Ethereal Group Ethereal 0.9.11
Ethereal Group Ethereal 0.9.12
Ethereal Group Ethereal 0.9.2
Ethereal Group Ethereal 0.9.3
Ethereal Group Ethereal 0.9.4
Ethereal Group Ethereal 0.9.5
Ethereal Group Ethereal 0.9.6
Ethereal Group Ethereal 0.9.7
Ethereal Group Ethereal 0.9.8
Ethereal Group Ethereal 0.9.9
SCO OpenLinux Server 3.1.1
SCO OpenLinux Workstation 3.1.1
Solution:
SCO have released an advisory (CSSA-2003-030.0) and fixes to address this issue. Affected users are advised to install the appropriate fix as soon as possible. Further information regarding the application of these fixes can be found in the referenced advisory. Fixes are linked below.
Conectiva has released a security advisory (CLSA-2003:719) and fixes to address this issue. Users are advised to upgrade as soon as possible.
Red Hat has released a security advisory (RHSA-2003:077-13) containing fixes which address this and other issues with ethereal. See referenced advisory for further details on obtaining and applying fixes.
Conectiva has released a security advisory (CLA-2003:662) and fixes to address this issue. Users are advised to upgrade as soon as possible.
Ethereal 0.9.13 is not vulnerable to this issue. Affected users are advised to upgrade to the newest version of Ethereal.
Red Hat has released upgraded RPMs which correct this vulnerability. Please see advisory RHSA-2003:203-01 (references section) for download links.
Updates are available for Yellow Dog Linux. These updates can be applied manually or by issuing the following command:
yum update ethereal
Ethereal Group Ethereal 0.9
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.1
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.10
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.11
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.12
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.2
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.3
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.4
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.5
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.6
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.7
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
Ethereal Group Ethereal 0.9.8
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz -
Yellow Dog ethereal-0.9.13-1.90.1a.ppc.rpm
ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-3.0/ppc/e thereal-0.9.13-1.90.1a.ppc.rpm -
Yellow Dog ethereal-gnome-0.9.13-1.90.1a.ppc.rpm
ftp://ftp.yellowdoglinux.com/pub/yellowdog/updates/yellowdog-3.0/ppc/e thereal-gnome-0.9.13-1.90.1a.ppc.rpm
Ethereal Group Ethereal 0.9.9
-
Ethereal Group ethereal-0.9.13.tar.gz
http://www.ethereal.com/distribution/ethereal-0.9.13.tar.gz
SCO OpenLinux Server 3.1.1
-
SCO ethereal-0.9.13-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-030.0/R PMS/ethereal-0.9.13-1.i386.rpm
SCO OpenLinux Workstation 3.1.1
-
SCO ethereal-0.9.13-1.i386.rpm
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-03 0.0/RPMS/ethereal-0.9.13-1.i386.rpm
References
Ethereal SPNEGO Dissector Denial Of Service Vulnerability
References:
References:
- CLSA-2003:719 ethereal (Conectiva)
- RHSA-2003:077-13 Updated Ethereal packages fix security issues (Red Hat)
- Several security problems in Ethereal 0.9.12 (Ethereal Group)
- YDU-20030718-2 Updated ethereal packages are available. (Yellow Dog)