Back
Multiple vulnerabilities in Ethereal versions 0.9.0 to 0.10.7
ethereal.com
21/12/2004 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution
This is member-only content.
Some features are reserved for our members. For full access, please login or become a member.
Details
CVSS (Max)
Not Available
OS
UNIX variants
Linux variants
Windows
Impact: Execute Arbitrary Code/Commands
Denial of Service
Access: Remote/Unauthenticated
CVE Names: CAN-2004-1142 CAN-2004-1141 CAN-2004-1140
CAN-2004-1139
Original Bulletin: http://www.ethereal.com/appnotes/enpa-sa-00016.html
- --------------------------BEGIN INCLUDED TEXT--------------------
Summary
- -------
Name: Multiple problems in Ethereal versions 0.9.0 to 0.10.7
Docid: enpa-sa-00016
Date: December 15, 2004
Versions affected: 0.9.0 up to and including 0.10.7
Severity: High
Details
- -------
Description:
Issues have been discovered in the following protocol dissectors:
* Matthew Bing discovered a bug in DICOM dissection that could make
Ethereal crash.
Versions affected: 0.10.4 - 0.10.7
CVE: CAN-2004-1139
* An invalid RTP timestamp could make Ethereal hang and create a large
temporary file, possibly filling available disk space.
Versions affected: 0.9.16 - 0.10.7
CVE: CAN-2004-1140
* The HTTP dissector could access previously-freed memory, causing a
crash.
Versions affected: 0.10.1 - 0.10.7
CVE: CAN-2004-1141
* Brian Caswell discovered that an improperly formatted SMB packet could
make Ethereal hang, maximizing CPU utilization.
Versions affected: 0.9.0 - 0.10.7
CVE: CAN-2004-1142
Impact:
It may be possible to make Ethereal crash or run arbitrary code by injecting a
purposefully malformed packet onto the wire or by convincing someone to read a
malformed packet trace file.