Security Advisory Updated ethereal packages are available

Advisory: RHSA-2002:088-06
Type: Security Advisory
Severity: N/A
Issued on: 2002-05-16
Last updated on: 2002-06-04
Affected Products: Red Hat Linux 7.2
Red Hat Linux 7.3
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-0012
CVE-2002-0013
CVE-2002-0353
CVE-2002-0401
CVE-2002-0402
CVE-2002-0403
CVE-2002-0404

Details

Updated ethereal packages are available which fix several security problems.

Ethereal is a package designed for monitoring network traffic on your
system. Several security issues have been found in Ethereal:

Due to improper string and error handling in Ethereal's ASN.1 parser, it is
possible for a malformed SNMP or LDAP packet to cause a memory allocation
or buffer overrun error in Ethereal versions before 0.9.2 (CAN-2002-0013
CAN-2002-0012)

The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to
cause a denial of service (crash) via a certain malformed packet, which
causes Ethereal to allocate memory incorrectly, possibly due to zero-length
fields. (CAN-2002-0353)

The SMB dissector in Ethereal prior to version 0.9.2 allows remote
attackers to cause a denial of service (crash) or execute arbitrary code
via malformed packets that cause Ethereal to dereference a NULL pointer.
(CAN-2002-0401)

A buffer overflow in X11 dissector in Ethereal before 0.9.3 allows
remote attackers to cause a denial of service (crash) and possibly
execute arbitrary code while Ethereal is parsing keysyms. (CAN-2002-0402)

The DNS dissector in Ethereal before 0.9.3 allows remote attackers to
cause a denial of service (CPU consumption) via a malformed packet
that causes Ethereal to enter an infinite loop. (CAN-2002-0403)

A vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote
attackers to cause a denial of service (memory consumption). (CAN-2002-0404)

Users of Ethereal should update to the errata packages containing Ethereal
version 0.9.4 which is not vulnerable to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 7.2

SRPMS:
ethereal-0.9.4-0.7.2.0.src.rpm
File outdated by:  RHSA-2003:323
    8ab27ce7ccaec617b4e5bee0f6cafc8a
 
IA-32:
ethereal-0.9.4-0.7.2.0.i386.rpm
File outdated by:  RHSA-2003:323
    a82a1bf914b31bc283c4786a6d005f5a
ethereal-gnome-0.9.4-0.7.2.0.i386.rpm
File outdated by:  RHSA-2003:323
    95b0e675cc1be0b5d59a2b3becf2420c
 
IA-64:
ethereal-0.9.4-0.7.2.0.ia64.rpm
File outdated by:  RHSA-2003:323
    c370c2585040f9174ebe6b20def17764
ethereal-gnome-0.9.4-0.7.2.0.ia64.rpm
File outdated by:  RHSA-2003:323
    2096533a5f9352ff47b4fd01302b7c92
 
Red Hat Linux 7.3

SRPMS:
ethereal-0.9.4-0.7.3.0.src.rpm
File outdated by:  RHSA-2003:323
    70022f6df52ad74013ab2901fe6f0e3d
 
IA-32:
ethereal-0.9.4-0.7.3.0.i386.rpm
File outdated by:  RHSA-2003:323
    52a3074dea1e4e9563558e523a659bc5
ethereal-gnome-0.9.4-0.7.3.0.i386.rpm
File outdated by:  RHSA-2003:323
    1650416f14b9f6a7cb15aa2f38f20bf4
 

References


Keywords

asn1, buffer, crash, ethereal, overflow


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/