Multiple Ethereal Protocol Dissector Vulnerabilities
BID:8951
Info
Multiple Ethereal Protocol Dissector Vulnerabilities
| Bugtraq ID: | 8951 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Nov 03 2003 12:00AM |
| Credit: | These issues were reported by the vendor. |
| Vulnerable: |
Turbolinux Turbolinux Desktop 10.0 Sun Linux 5.0.7 SGI ProPack 2.3 SGI ProPack 2.2.1 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 9.2 Mandriva Linux Mandrake 9.1 ppc Mandriva Linux Mandrake 9.1 Ethereal Group Ethereal 0.9.15 Ethereal Group Ethereal 0.9.14 Ethereal Group Ethereal 0.9.13 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.9.16 |
Discussion
Multiple Ethereal Protocol Dissector Vulnerabilities
Multiple Ethereal protocol dissectors are prone to remotely exploitable vulnerabilities. The GTP, ISAKMP, MEGACO and SOCKS dissectors are affected by these issues. These issues may be exploited by causing Ethereal to process a malformed packet, either while Ethereal is monitoring live network traffic or via a packet trace. Successful exploitation could lead to code execution or denial of service attacks against Ethereal.
Multiple Ethereal protocol dissectors are prone to remotely exploitable vulnerabilities. The GTP, ISAKMP, MEGACO and SOCKS dissectors are affected by these issues. These issues may be exploited by causing Ethereal to process a malformed packet, either while Ethereal is monitoring live network traffic or via a packet trace. Successful exploitation could lead to code execution or denial of service attacks against Ethereal.
Exploit / POC
Multiple Ethereal Protocol Dissector Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Ethereal Protocol Dissector Vulnerabilities
Solution:
Mandrake has released an advisory (MDKSA-2003:114) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory. Fixes are linked below.
Turbolinux have released an advisory (TLSA-2003-64) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory.
Red Hat has released an advisory (RHSA-2003:324-09) that addresses this issue on Red Hat Enterprise edition Linux. Customers who are potentially affected by this vulnerability are advised to apply appropriate fixes as soon as possible. Customers can download these fixes from the Red Hat network; further information is available in the referenced advisory.
Conectiva has released advisories CLA-2003:780 and CLSA-2003:793 to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released a security advisory (RHSA-2003:323-01) containing fixes to address this issue. Users are advised to upgrade as soon as possible.
SGI has released an advisory (20031101-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10032) containing updated RPM packages relating to a number of different BIDS.
Patch 10032 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10032, please see the attached advisory.
Gentoo has released an advisory that includes updates for these issues. These updates may be applied with the following commands:
emerge sync
emerge '>=sys-libs/glibc-2.2.5'
emerge clean
Ethereal 0.9.16 has been released to address these issues.
RedHat has released fixes for the experimental operating system Fedora. These fixes address Ethereal Group Ethereal 0.9.13 shipped with Fedora Core1.
Sun has released fixes for Sun Linux version 5.0.7.
Debian has released security advisory DSA 407-1 to address this issue.
Ethereal Group Ethereal 0.9
Ethereal Group Ethereal 0.9.1
Ethereal Group Ethereal 0.9.10
Ethereal Group Ethereal 0.9.11
Ethereal Group Ethereal 0.9.12
Ethereal Group Ethereal 0.9.13
Ethereal Group Ethereal 0.9.14
Ethereal Group Ethereal 0.9.15
Ethereal Group Ethereal 0.9.2
Ethereal Group Ethereal 0.9.3
Ethereal Group Ethereal 0.9.4
Ethereal Group Ethereal 0.9.5
Ethereal Group Ethereal 0.9.6
Ethereal Group Ethereal 0.9.7
Ethereal Group Ethereal 0.9.8
Ethereal Group Ethereal 0.9.9
Turbolinux Turbolinux Desktop 10.0
Sun Linux 5.0.7
Mandriva Linux Mandrake 9.1 ppc
Mandriva Linux Mandrake 9.1
Mandriva Linux Mandrake 9.2
Solution:
Mandrake has released an advisory (MDKSA-2003:114) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory. Fixes are linked below.
Turbolinux have released an advisory (TLSA-2003-64) to address this issue. Users who are potentially affected by this vulnerability are advised to apply relative fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory.
Red Hat has released an advisory (RHSA-2003:324-09) that addresses this issue on Red Hat Enterprise edition Linux. Customers who are potentially affected by this vulnerability are advised to apply appropriate fixes as soon as possible. Customers can download these fixes from the Red Hat network; further information is available in the referenced advisory.
Conectiva has released advisories CLA-2003:780 and CLSA-2003:793 to address these issues. Please see the attached advisory for details on obtaining and applying fixes.
Red Hat has released a security advisory (RHSA-2003:323-01) containing fixes to address this issue. Users are advised to upgrade as soon as possible.
SGI has released an advisory (20031101-01-U) pertaining to their ProPack Linux distribution. The advisory has been released in response to a number of RHSA advisories, and includes a patch (Patch 10032) containing updated RPM packages relating to a number of different BIDS.
Patch 10032 can be obtained via the following link:
http://support.sgi.com/
For information regarding how to obtain individual RPM packages included in Patch 10032, please see the attached advisory.
Gentoo has released an advisory that includes updates for these issues. These updates may be applied with the following commands:
emerge sync
emerge '>=sys-libs/glibc-2.2.5'
emerge clean
Ethereal 0.9.16 has been released to address these issues.
RedHat has released fixes for the experimental operating system Fedora. These fixes address Ethereal Group Ethereal 0.9.13 shipped with Fedora Core1.
Sun has released fixes for Sun Linux version 5.0.7.
Debian has released security advisory DSA 407-1 to address this issue.
Ethereal Group Ethereal 0.9
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.1
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.10
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.11
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.12
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.13
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html -
Fedora ethereal-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-0.9.16-2.FC1.1.i386.rpm -
Fedora ethereal-debuginfo-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-debuginfo-0.9.16-2.FC1.1.i386.rpm -
Fedora ethereal-gnome-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-gnome-0.9.16-2.FC1.1.i386.rpm -
RedHat ethereal-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-0.9.16-2.FC1.1.i386.rpm -
RedHat ethereal-debuginfo-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /debug/ethereal-debuginfo-0.9.16-2.FC1.1.i386.rpm -
RedHat ethereal-gnome-0.9.16-2.FC1.1.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/i386 /ethereal-gnome-0.9.16-2.FC1.1.i386.rpm
Ethereal Group Ethereal 0.9.14
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html -
S.u.S.E. ethereal-0.9.14-115.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/ethereal-0.9.14-1 15.i586.patch.rpm
Ethereal Group Ethereal 0.9.15
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.2
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.3
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.4
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.5
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.6
-
Conectiva ethereal-0.9.6-246.i586.rpm
ftp://ul.conectiva.com.br/updates/1.0/RPMS.core/ethereal-0.9.6-246.i58 6.rpm -
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.7
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Ethereal Group Ethereal 0.9.8
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html -
Red Hat ethereal-0.9.16-0.72.1.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/ethereal-0.9.16-0.72.1.i386.rp m -
Red Hat ethereal-0.9.16-0.72.1.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/ethereal-0.9.16-0.72.1.ia64.rp m -
Red Hat ethereal-0.9.16-0.73.1.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/ethereal-0.9.16-0.73.1.i386.rp m -
Red Hat ethereal-0.9.16-0.80.1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/ethereal-0.9.16-0.80.1.i386.rp m -
Red Hat ethereal-0.9.16-0.90.1.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/ethereal-0.9.16-0.90.1.i386.rpm -
Red Hat ethereal-gnome-0.9.16-0.72.1.i386.rpm
ftp://updates.redhat.com/7.2/en/os/i386/ethereal-gnome-0.9.16-0.72.1.i 386.rpm -
Red Hat ethereal-gnome-0.9.16-0.72.1.ia64.rpm
ftp://updates.redhat.com/7.2/en/os/ia64/ethereal-gnome-0.9.16-0.72.1.i a64.rpm -
Red Hat ethereal-gnome-0.9.16-0.73.1.i386.rpm
ftp://updates.redhat.com/7.3/en/os/i386/ethereal-gnome-0.9.16-0.73.1.i 386.rpm -
Red Hat ethereal-gnome-0.9.16-0.80.1.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/ethereal-gnome-0.9.16-0.80.1.i 386.rpm -
Red Hat ethereal-gnome-0.9.16-0.90.1.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/ethereal-gnome-0.9.16-0.90.1.i38 6.rpm
Ethereal Group Ethereal 0.9.9
-
Ethereal Group Ethereal 0.9.16
http://www.ethereal.com/download.html
Turbolinux Turbolinux Desktop 10.0
-
TurboLinux ethereal-0.9.16-1.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/ethereal-0.9.16-1.i586.rpm
Sun Linux 5.0.7
-
Sun ethereal-0.9.16-0.72.1.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/ethereal-0.9.16-0.72.1.i386.rpm -
Sun ethereal-gnome-0.9.16-0.72.1.i386.rpm
ftp://ftp.cobalt.sun.com/pub/products/sunlinux/5.0/en/updates/i386/RPM S/ethereal-gnome-0.9.16-0.72.1.i386.rpm
Mandriva Linux Mandrake 9.1 ppc
-
Mandrake ethereal-0.9.16-2.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPCFTP Folder: ppc/9.1/RPMS/
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 9.1
-
Mandrake ethereal-0.9.16-2.1.91mdk.i586.rpm
Mandrake Linux 9.1FTP Folder: 9.1/RPMS
http://www.mandrakesecure.net/en/ftp.php
Mandriva Linux Mandrake 9.2
-
Mandrake ethereal-0.9.16-2.1.92mdk.i586.rpm
Mandrake Linux 9.2FTP Folder: 9.2/RPMS/
http://www.mandrakesecure.net/en/ftp.php
References
Multiple Ethereal Protocol Dissector Vulnerabilities
References:
References:
- CLSA-2003:793 (Conectiva)
- RHSA-2003:324-09 Updated Ethereal packages fix security issues (Red Hat)
- Security problems in Ethereal 0.9.15 (Ethereal Group)