Back

Multiple problems in Ethereal versions 0.8.20 to 0.10.13

ethereal.com
12/01/2006 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution

This is member-only content.

Some features are reserved for our members. For full access, please login or become a member.

Details

CVSS (Max)
Not Available
Products
XXXXXXXXXXXXXXXXXXXXXXXXXX
Publisher
Ethereal
OS
UNIX variants (UNIX, Linux, OSX) Windows Impact: Execute Arbitrary Code/Commands Denial of Service Access: Remote/Unauthenticated CVE Names: CVE-2005-3313 CVE-2005-3651 CVE-2005-4585 Original Bulletin: http://www.ethereal.com/appnotes/enpa-sa-00022.html - --------------------------BEGIN INCLUDED TEXT-------------------- Summary Name: Multiple problems in Ethereal versions 0.8.20 to 0.10.13 Docid: enpa-sa-00022 Date: December 27, 2005 Versions affected: 0.8.20 up to and including 0.10.13 Severity: High Details Description: Three security issues have turned up since Ethereal 0.10.13 was released: * The IRC dissector could go into an infinite loop. Versions affected: 0.10.13. * The GTP dissector could go into an infinite loop. Versions affected: 0.9.1 to 0.10.13. * iDefense found a buffer overflow in the OSPF dissector. Versions affected: 0.8.20 to 0.10.13. CVE: CAN-2005-3651 Impact: It may be possible to make Ethereal crash, use up available system resources, or run arbitrary code by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed trace file.
CVE(s)
XXXXXXXXXXXXX XXXXXXXXXXXXX XXXXXXXXXXXXX