Red Hat Bugzilla – Bug 145483
CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)
Last modified: 2007-11-30 17:07:15 EST
*** This bug has been split off bug 145481 *** ------- Original comment by Josh Bressers (Security Response Team) on 2005.01.18 16:16 ------- Gerald Combs reported multiple issues in Ethereal to vendor-sec >Ethereal 0.10.9 is scheduled to be released tomorrow (January 18). It >will address the following issues: > > The COPS dissector could go into an infinite loop. > Versions affected: 0.10.6 - 0.10.8 > Fixed in revision: 13075 CAN-2005-0006 > The DLSw dissector could cause an assertion, making Ethereal exit > prematurely. > Versions affected: 0.10.6 - 0.10.8 > Fixed in revision: 13012 CAN-2005-0007 > The DNP dissector could cause memory corruption. > Versions affected: 0.10.5 - 0.10.8 > Fixed in revision: 13083 CAN-2005-0008 > The Gnutella dissector could cuase an assertion, making Ethereal exit > prematurely. > Versions affected: 0.10.6 - 0.10.8 > Fixed in revision: 13032 CAN-2005-0009 > The MMSE dissector could free statically-allocated memory. > Versions affected: 0.10.4 - 0.10.8 > Fixed in revision: 12801 CAN-2005-0010 > The X11 dissector is vulnerable to a string buffer overflow. > Versions affected: 0.8.10 - 0.10.8 > Fixed in revision: 13057 CAN-2005-0084
Package updated to ethereal-0.10.9
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-037.html