Bug 145481 - CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)
CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-...
Product: Red Hat Enterprise Linux 3
Classification: Red Hat
Component: ethereal (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Radek Vokal
: Security
Depends On:
  Show dependency treegraph
Reported: 2005-01-18 16:16 EST by Josh Bressers
Modified: 2007-11-30 17:07 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-02-02 07:07:38 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2005-01-18 16:16:47 EST
Gerald Combs reported multiple issues in Ethereal to vendor-sec

>Ethereal 0.10.9 is scheduled to be released tomorrow (January 18).  It
>will address the following issues:
> The COPS dissector could go into an infinite loop.
> Versions affected: 0.10.6 - 0.10.8
> Fixed in revision: 13075


> The DLSw dissector could cause an assertion, making Ethereal exit
> prematurely.
> Versions affected: 0.10.6 - 0.10.8
> Fixed in revision: 13012


> The DNP dissector could cause memory corruption.
> Versions affected: 0.10.5 - 0.10.8
> Fixed in revision: 13083


> The Gnutella dissector could cuase an assertion, making Ethereal exit
> prematurely.
> Versions affected: 0.10.6 - 0.10.8
> Fixed in revision: 13032


> The MMSE dissector could free statically-allocated memory.
> Versions affected: 0.10.4 - 0.10.8
> Fixed in revision: 12801


> The X11 dissector is vulnerable to a string buffer overflow.
> Versions affected: 0.8.10 - 0.10.8
> Fixed in revision: 13057

Comment 1 Josh Bressers 2005-01-18 16:19:04 EST

I'm thinking we should just wait for the new ethereal version, then re-roll the
RHEL errata packages.
Comment 2 Josh Bressers 2005-01-18 16:19:44 EST
This issue is also going to affect RHEL2.1
Comment 3 Radek Vokal 2005-01-19 03:18:36 EST
We should ship ethereal labeled as dangerous software and only for skilled
users. Of course waiting for 0.10.9 makes sence .. 
Comment 4 Radek Vokal 2005-01-25 08:42:52 EST
Ethereal updated to version 0.10.9
Comment 5 Mark J. Cox (Product Security) 2005-02-02 07:07:38 EST
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.