Gentoo: ethereal arbitrary code execution vulnerability
Summary
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-13
from advisory: "It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file."
Read the full advisory at
SOLUTION
It is recommended that all Gentoo Linux users who are running net-analyzer/ethereal upgrade to ethereal as follows
emerge sync emerge ethereal emerge clean
aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background