|
|
| |
|
| |
Ethereal 0.9.6 fixes potential remote code execution vulnerability
| Package(s): | ethereal |
CVE #(s): | CAN-2002-0834
CAN-2002-0821
CAN-2002-0822
|
| Created: | September 4, 2002 |
Updated: | September 11, 2002 |
| Description: |
Ethereal 0.9.6 was released
on August 20, 2002 fixing a serious
buffer overflow vulnerability in the ISIS protocol dissector in Ethereal 0.9.5 and earlier versions.
It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.
Ethereal 0.9.4 has multiple buffer overflow and other
vulnerabilities hat are best delt with by upgrading to 0.9.6.
These vulnerabilities may allow remote attackers
to cause a denial of service or execute arbitrary code.
Updating now, rather than later, is recommended. |
| Alerts: |
|
( Log in to post comments)
|
|
|