Bug 171063 - CAN-2005-3241 Multiple ethereal issues (CAN-2005-3242 CAN-2005-3243 CAN-2005-3244 CAN-2005-3245 CAN-2005-3246 CAN-2005-3247 CAN-2005-3248 CAN-2005-3249 CAN-2005-3184)
CAN-2005-3241 Multiple ethereal issues (CAN-2005-3242 CAN-2005-3243 CAN-2005-...
Status: CLOSED ERRATA
Product: Fedora
Classification: Fedora
Component: ethereal (Show other bugs)
4
All Linux
medium Severity medium
: ---
: ---
Assigned To: Radek Vokal
reported=20051014,public=20051019,imp...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-10-17 16:14 EDT by Josh Bressers
Modified: 2007-11-30 17:11 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-10-21 04:27:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Josh Bressers 2005-10-17 16:14:03 EDT
+++ This bug was initially created as a clone of Bug #171062 +++

Ethereal 0.10.13 is scheduled to be released, which fixes the following issues:

  The ISAKMP dissector could exhaust system memory. (CAN-2005-3241)
  Fixed in: r15163
  Bug IDs: none
  Versions affected: 0.10.11 to 0.10.12.

  The FC-FCS dissector could exhaust system memory. (CAN-2005-3241)
  Fixed in: r15204
  Bug IDs: 312
  Versions affected: 0.9.0 to 0.10.12.

  The RSVP dissector could exhaust system memory. (CAN-2005-3241)
  Fixed in: r15206, r15600
  Bug IDs: 311, 314, 382
  Versions affected: 0.9.4 to 0.10.12.

  The ISIS LSP dissector could exhaust system memory. (CAN-2005-3241)
  Fixed in: r15245
  Bug IDs: 320, 326
  Versions affected: 0.8.18 to 0.10.12.

  The IrDA dissector could crash. (CAN-2005-3242)
  Fixed in: r15265, r15267
  Bug IDs: 328, 329, 330, 334, 335, 336
  Versions affected: 0.10.0 to 0.10.12.

  The SLIMP3 dissector could overflow a buffer. (CAN-2005-3243)
  Fixed in: r15279
  Bug IDs: 327
  Versions affected: 0.9.1 to 0.10.12.

  The BER dissector was susceptible to an infinite loop. (CAN-2005-3244)
  Fixed in: r15292
  Bug IDs: none
  Versions affected: 0.10.3 to 0.10.12.

  The SCSI dissector could dereference a null pointer and crash. (CAN-2005-3246)
  Fixed in: r15289
  Bug IDs: none
  Versions affected: 0.10.3 to 0.10.12.

  If the "Dissect unknown RPC program numbers" option was enabled,
  the ONC RPC dissector might be able to exhaust system memory.
  This option is disabled by default. (CAN-2005-3245)
  Fixed in: r15290
  Bug IDs: none
  Versions affected: 0.7.7 to 0.10.12.

  The sFlow dissector could dereference a null pointer and crash (CAN-2005-3246)
  Fixed in: r15375
  Bug IDs: 356
  Versions affected: 0.9.14 to 0.10.12.

  The RTnet dissector could dereference a null pointer and crash (CAN-2005-3246)
  Fixed in: r15673
  Bug IDs: none
  Versions affected: 0.10.8 to 0.10.12.

  The SigComp UDVM could go into an infinite loop or crash. (CAN-2005-3247)
  Fixed in: r15715, r15901, r15919
  Bug IDs: none
  Versions affected: 0.10.12.

  If SMB transaction payload reassembly is enabled the SMB
  dissector could crash. This preference is disabled by default. (CAN-2005-3242)
  Fixed in: r15789
  Bug IDs: 421
  Versions affected: 0.9.7 to 0.10.12.

  The X11 dissector could attempt to divide by zero. (CAN-2005-3248)
  Fixed in: r15927
  Bug IDs: none
  Versions affected: 0.10.1 to 0.10.12.

  The AgentX dissector could overflow a buffer. (CAN-2005-3243)
  Fixed in: r16003
  Bug IDs: none
  Versions affected: 0.10.10 to 0.10.12.

  The WSP dissector could free an invalid pointer. (CAN-2005-3249)
  Fixed in: r16220
  Bug IDs: none
  Versions affected: 0.10.1 to 0.10.12.

  iDEFENSE found a buffer overflow in the SRVLOC dissector. (CAN-2005-3184)
  Fixed in: r16206
  Bug IDs: none
  Versions affected: 0.10.0 to 0.10.12.
Comment 1 Josh Bressers 2005-10-17 16:14:51 EDT
These issues also affect FC3
Comment 2 Josh Bressers 2005-10-19 18:17:25 EDT
Public, lifting embargo.
Comment 3 Fedora Update System 2005-10-20 10:31:10 EDT
From User-Agent: XML-RPC

ethereal-0.10.13-1.FC4.2 has been pushed for FC4, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.
Comment 4 Radek Vokal 2005-10-21 04:27:35 EDT
ethereal-0.10.13-1.FC3.1 has been pushed for FC3, which should resolve this
issue.  If these problems are still present in this version, then please make
note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.