Red Hat Bugzilla – Bug 150705
CAN-2005-0699 Multiple ethereal issues (CAN-2005-0704 CAN-2005-0705)
Last modified: 2007-11-30 17:07:16 EST
Ethereal 0.10.10 is scheduled to be released on Thursday, March 10. It addresses the following security issues: The Etheric dissector was susceptible to a buffer overflow. Versions affected: 0.10.7 to 0.10.9 Fixed in revision: 13176 The GPRS-LLC dissector could crash if the "ignore cipher bit" option was enabled. Versions affected: 0.10.7 to 0.10.9 Fixed in revisions: 13386 (further improvements in 13549 and 13571) The 3GPP2 A11 dissector was susceptible to a buffer overflow. Versions affected: 0.10.3 to 0.10.9 Fixed in revision: 13574 CAN-2005-0699
Radek, this is a heads up. I imagine we'll upgrade as before? Additionally, RHEL2.1 and RHEL3 are affected.
The Etheric dissector was susceptible to a buffer overflow. CAN-2005-0704 The GPRS-LLC dissector could crash if the "ignore cipher bit" option CAN-2005-0705 The 3GPP2 A11 dissector was susceptible to a buffer overflow. CAN-2005-0699
Ethereal 0.10.10 has been released http://www.ethereal.com/news/item_20050311_01.html
RHSA-2005:306-02 created for EL4. Others are comming ..
*** Bug 151035 has been marked as a duplicate of this bug. ***
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-306.html