Ethereal: Multiple vulnerabilities in protocol dissectors
Ethereal is vulnerable to numerous vulnerabilities, potentially resulting
in the execution of arbitrary code.
Ethereal
April 27, 2006
April 27, 2006: 01
130505
remote
0.99.0
0.99.0
Ethereal is a feature-rich network protocol analyzer.
Coverity discovered numerous vulnerabilities in versions of
Ethereal prior to 0.99.0, including:
-
buffer overflows in the ALCAP (CVE-2006-1934), COPS (CVE-2006-1935)
and telnet (CVE-2006-1936) dissectors.
- buffer overflows
in the NetXray/Windows Sniffer and Network Instruments file code
(CVE-2006-1934).
For further details please consult the
references below.
An attacker might be able to exploit these vulnerabilities to crash
Ethereal or execute arbitrary code with the permissions of the user
running Ethereal, which could be the root user.
There is no known workaround at this time.
All Ethereal users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/ethereal-0.99.0"
CVE-2006-1932
CVE-2006-1933
CVE-2006-1934
CVE-2006-1935
CVE-2006-1936
CVE-2006-1937
CVE-2006-1938
CVE-2006-1939
CVE-2006-1940
Ethereal enpa-sa-00023
jaervosz
jaervosz