First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 22950
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Daniel Ahlberg (RETIRED) <aliz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 22950 depends on: 22774 Show dependency tree
Bug 22950 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2003-06-16 13:39 0000
SUMMARY 
 
 
 
 
Name: Several security problems in Ethereal 0.9.12 
 
 Docid: enpa-sa-00010 
 
 
 Date: June 11, 2003 
 
 
 Severity: High 
 
 
  
 
 
 
 
 
 
DETAILS 
 
 
 
 
Description: 
 
 Further source code auditing by Timo Sirainen has turned up several string handling flaws in various 
protocol dissectors. Separate security problems were discovered by other people: 
 
 
  
 
The DCERPC dissector could try to allocate too much memory while trying to decode an NDR string.  
Bad IPv4 or IPv6 prefix lengths could cause an overflow in the OSI dissector.  
The SPNEGO dissector could segfault while parsing an invalid ASN.1 value.  
The tvb_get_nstringz0() routine incorrectly handled a zero-length buffer size.  
The BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI dissectors handled strings 
improperly.  
 
Impact: 
 
 
 It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed 
packet onto the wire, or by convincing someone to read a malformed packet trace file.  
 
 
Resolution: 
 
 
 Upgrade to 0.9.13.

------- Comment #1 From Daniel Ahlberg (RETIRED) 2003-06-25 15:39:28 0000 -------
glsa sent 

First Last Prev Next    No search results available      Search page      Enter new bug