LWN.net Logo

ethereal - format string vulnerability

Package(s):ethereal CVE #(s):CAN-2003-0081
Created:March 10, 2003 Updated:June 12, 2003
Description: The SOCKS dissector in Ethereal 0.9.9 is susceptible to a format string overflow. This vulnerability has been present in Ethereal since the SOCKS dissector was introduced in version 0.8.7. It was discovered by Georgi Guninski. Additionally, the NTLMSSP code is susceptible to a heap overflow. All users of Ethereal 0.9.9 and below are encouraged to upgrade. See the full advisory for additional information.
Alerts:
Mandrake MDKSA-2003:051 2003-03-24
Red Hat RHSA-2003:076-01 2003-04-23
Conectiva CLA-2003:627 2003-04-16
SuSE SuSE-SA:2003:019 2003-03-21
Debian DSA-258-1 2003-03-10
Gentoo 200303-10 2003-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds