LWN.net Logo

Red Hat alert RHSA-2004:002-01 (ethereal)

From:  bugzilla@redhat.com
To:  enterprise-watch-list@redhat.com
Subject:  [RHSA-2004:002-01] Updated Ethereal packages fix security issues
Date:  Tue, 20 Jan 2004 11:46 -0500

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated Ethereal packages fix security issues Advisory ID: RHSA-2004:002-01 Issue date: 2004-01-05 Updated on: 2004-01-05 Product: Red Hat Enterprise Linux Keywords: Cross references: Obsoletes: RHSA-2003:324 CVE Names: CAN-2003-1012 CAN-2003-1013 - --------------------------------------------------------------------- 1. Topic: Updated Ethereal packages that fix two security vulnerabilities are now available. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 3 - i386 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: Ethereal is a program for monitoring network traffic. Two security issues have been found that affect Ethereal. By exploiting these issues it may be possible to make Ethereal crash by injecting an intentionally malformed packet onto the wire or by convincing someone to read a malformed packet trace file. It is not known if these issues could allow arbitrary code execution. The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-1012 to this issue. The Q.931 dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-1013 to this issue. Users of Ethereal should update to these erratum packages containing Ethereal version 0.10.0, which is not vulnerable to these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/bugzilla for more info): 112224 - CAN-2003-1012/3 Ethereal security issues 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm ia64: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm ia64: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.i386.rpm ia64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.ia64.rpm ppc: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.ppc.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.ppc.rpm s390: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.s390.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.s390.rpm s390x: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.s390x.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.s390x.rpm x86_64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.x86_64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.i386.rpm Red Hat Enterprise Linux WS version 3: SRPMS: ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.i386.rpm ia64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.ia64.rpm x86_64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.x86_64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.x86_64.rpm 7. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- 4864cdc433f62bd2a39283c95e8cba5e 2.1AS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm 2eae83d66a522f3ff16a928a3beb3618 2.1AS/en/os/i386/ethereal-0.10.0a-0.AS21.1.i386.rpm 1361bf4fcb37f3b06757dc5d941764b2 2.1AS/en/os/i386/ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm e446e723263054aa0c7b6db29a9465c8 2.1AS/en/os/ia64/ethereal-0.10.0a-0.AS21.1.ia64.rpm a948b4a7c7fe42d576e1d84c26f2d581 2.1AS/en/os/ia64/ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm 4864cdc433f62bd2a39283c95e8cba5e 2.1AW/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm e446e723263054aa0c7b6db29a9465c8 2.1AW/en/os/ia64/ethereal-0.10.0a-0.AS21.1.ia64.rpm a948b4a7c7fe42d576e1d84c26f2d581 2.1AW/en/os/ia64/ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm 4864cdc433f62bd2a39283c95e8cba5e 2.1ES/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm 2eae83d66a522f3ff16a928a3beb3618 2.1ES/en/os/i386/ethereal-0.10.0a-0.AS21.1.i386.rpm 1361bf4fcb37f3b06757dc5d941764b2 2.1ES/en/os/i386/ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm 4864cdc433f62bd2a39283c95e8cba5e 2.1WS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm 2eae83d66a522f3ff16a928a3beb3618 2.1WS/en/os/i386/ethereal-0.10.0a-0.AS21.1.i386.rpm 1361bf4fcb37f3b06757dc5d941764b2 2.1WS/en/os/i386/ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm 835218c09d0387840f6d699d62acd9dc 3AS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm 9fe833e248eff6f167748d4da3ac1cde 3AS/en/os/i386/ethereal-0.10.0a-0.30E.1.i386.rpm b17a76f3181e402256075ee6a2c2fd0b 3AS/en/os/i386/ethereal-gnome-0.10.0a-0.30E.1.i386.rpm 8123332d244b6b24216fa41da28711bd 3AS/en/os/ia64/ethereal-0.10.0a-0.30E.1.ia64.rpm 8833776003ed0e2b07e647cca78242f8 3AS/en/os/ia64/ethereal-gnome-0.10.0a-0.30E.1.ia64.rpm c4df4fc7b7d5ed58f36443994d4007a2 3AS/en/os/ppc/ethereal-0.10.0a-0.30E.1.ppc.rpm 5a4b119482b128ffa0e67c2abc4dec24 3AS/en/os/ppc/ethereal-gnome-0.10.0a-0.30E.1.ppc.rpm cf00042f8127518679abb63635c6bc9e 3AS/en/os/s390/ethereal-0.10.0a-0.30E.1.s390.rpm fb0dab4f3f72af4355e714c14cd01494 3AS/en/os/s390/ethereal-gnome-0.10.0a-0.30E.1.s390.rpm b539c7d2583ad559492a3bd9827d15b2 3AS/en/os/s390x/ethereal-0.10.0a-0.30E.1.s390x.rpm 434b52beb8678ef4aa804e55e4c023f5 3AS/en/os/s390x/ethereal-gnome-0.10.0a-0.30E.1.s390x.rpm 0a04a969ca381dd61a086dcffb73525a 3AS/en/os/x86_64/ethereal-0.10.0a-0.30E.1.x86_64.rpm 26e6eb9def443d67a48ba25adf7d90d4 3AS/en/os/x86_64/ethereal-gnome-0.10.0a-0.30E.1.x86_64.rpm 835218c09d0387840f6d699d62acd9dc 3ES/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm 9fe833e248eff6f167748d4da3ac1cde 3ES/en/os/i386/ethereal-0.10.0a-0.30E.1.i386.rpm b17a76f3181e402256075ee6a2c2fd0b 3ES/en/os/i386/ethereal-gnome-0.10.0a-0.30E.1.i386.rpm 835218c09d0387840f6d699d62acd9dc 3WS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm 9fe833e248eff6f167748d4da3ac1cde 3WS/en/os/i386/ethereal-0.10.0a-0.30E.1.i386.rpm b17a76f3181e402256075ee6a2c2fd0b 3WS/en/os/i386/ethereal-gnome-0.10.0a-0.30E.1.i386.rpm 8123332d244b6b24216fa41da28711bd 3WS/en/os/ia64/ethereal-0.10.0a-0.30E.1.ia64.rpm 8833776003ed0e2b07e647cca78242f8 3WS/en/os/ia64/ethereal-gnome-0.10.0a-0.30E.1.ia64.rpm 0a04a969ca381dd61a086dcffb73525a 3WS/en/os/x86_64/ethereal-0.10.0a-0.30E.1.x86_64.rpm 26e6eb9def443d67a48ba25adf7d90d4 3WS/en/os/x86_64/ethereal-gnome-0.10.0a-0.30E.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://www.redhat.com/security/keys.html You can verify each package with the following command: rpm --checksig -v <filename> If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum <filename> 8. References: http://www.ethereal.com/appnotes/enpa-sa-00012.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-1012 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-1013 9. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://www.redhat.com/solutions/security/news/contact.html Copyright 2003 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFADVtfXlSAg2UNWIIRAikeAKC7giztsZTBqz1NDae5vpI4ShmqsQCeJK+A MlQDjtwWdU9fuwfTt8yeaJA= =c+wG -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list Enterprise-watch-list@redhat.com https://www.redhat.com/mailman/listinfo/enterprise-watch-list


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds