Gentoo: Etherial multiple vulnerabilities
Summary
----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
- - --------------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200311-04 - - ---------------------------------------------------------------------------
GLSA: 200311-04 package: net-analyzer/ethereal summary: Security problems in Ethereal 0.9.15 severity: normal Gentoo bug: 32691 date: 2003-11-22 CVE: none exploit: remote affected: <0.9.16 fixed:>=0.9.16
DESCRIPTION:
Quote from <
Potential security issues have been discovered in the following protocol dissectors:
* An improperly formatted GTP MSISDN string could cause a buffer overflow.
* A malformed ISAKMP or MEGACO packet could make Ethereal or Tethereal crash.
* The SOCKS dissector was susceptible to a heap overlfow.
Impact:
It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire...Read the Full Advisory
Resolution
References
Availability
Concerns
Background