Back
Multiple problems in Ethereal versions 0.8.20 to 0.10.13
ethereal.com
12/01/2006 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution
This is member-only content.
Some features are reserved for our members. For full access, please login or become a member.
Details
CVSS (Max)
Not Available
Products
XXXXXXXXXXXXXXXXXXXXXXXXXX
Publisher
Ethereal
OS
UNIX variants (UNIX, Linux, OSX)
Windows
Impact: Execute Arbitrary Code/Commands
Denial of Service
Access: Remote/Unauthenticated
CVE Names: CVE-2005-3313 CVE-2005-3651 CVE-2005-4585
Original Bulletin: http://www.ethereal.com/appnotes/enpa-sa-00022.html
- --------------------------BEGIN INCLUDED TEXT--------------------
Summary
Name: Multiple problems in Ethereal versions 0.8.20 to 0.10.13
Docid: enpa-sa-00022
Date: December 27, 2005
Versions affected: 0.8.20 up to and including 0.10.13
Severity: High
Details
Description:
Three security issues have turned up since Ethereal 0.10.13 was released:
* The IRC dissector could go into an infinite loop.
Versions affected: 0.10.13.
* The GTP dissector could go into an infinite loop.
Versions affected: 0.9.1 to 0.10.13.
* iDefense found a buffer overflow in the OSPF dissector.
Versions affected: 0.8.20 to 0.10.13. CVE: CAN-2005-3651
Impact:
It may be possible to make Ethereal crash, use up available system
resources, or run arbitrary code by injecting a purposefully malformed
packet onto the wire or by convincing someone to read a malformed trace
file.
CVE(s)
XXXXXXXXXXXXX
XXXXXXXXXXXXX
XXXXXXXXXXXXX