LWN.net Logo

Ethereal 0.9.6 fixes potential remote code execution vulnerability

Package(s):ethereal CVE #(s):CAN-2002-0834 CAN-2002-0821 CAN-2002-0822
Created:September 4, 2002 Updated:September 11, 2002
Description: Ethereal 0.9.6 was released on August 20, 2002 fixing a serious buffer overflow vulnerability in the ISIS protocol dissector in Ethereal 0.9.5 and earlier versions.
It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.

Ethereal 0.9.4 has multiple buffer overflow and other vulnerabilities hat are best delt with by upgrading to 0.9.6. These vulnerabilities may allow remote attackers to cause a denial of service or execute arbitrary code.

Updating now, rather than later, is recommended.

Alerts:
Debian DSA-162-1 2002-09-06
Eridani ERISA-2002:040 2002-09-03
Gentoo ethereal-20020830 2002-08-30
Red Hat RHSA-2002:169-13 2002-08-28

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds