LWN.net Logo

ethereal - Various security issues in Ethereal

Package(s):ethereal CVE #(s):CAN-2002-1355 CAN-2002-1356
Created:January 9, 2003 Updated:January 14, 2003
Description: Ethereal is a package designed for monitoring network traffic on your system. Several security issues have been found in the Ethereal packages.

Multiple integer signedness errors in the BGP dissector in Ethereal 0.9.7 and earlier allow remote attackers to cause a denial of service (infinite loop) via malformed messages. This problem was discovered by Silvio Cesare. CAN-2002-1355

Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the LMP, PPP, or TDS dissectors. CAN-2002-1356

Users of Ethereal should update to the erratum packages containing Ethereal version 0.9.8 which is not vulnerable to these issues.

Alerts:
Red Hat RHSA-2002:290-07 2003-01-08

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds