Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: ethereal (200306-13)
Date: Wed, 25 Jun 2003 22:37:55
Message-Id: 20030625223632.1F8E93375F@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200306-13
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : ethereal
9           SUMMARY : arbitrary code execution
10              DATE : 2003-06-25 22:36 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <ethereal-0.9.13
13     FIXED VERSION : >=ethereal-0.9.13
14               CVE : CAN-2003-0432
15
16 - - - ---------------------------------------------------------------------
17
18 from advisory:
19 "It may be possible to make Ethereal crash or run arbitrary code by
20 injecting a purposefully malformed packet onto the wire, or by convincing
21 someone to read a malformed packet trace file."
22
23 Read the full advisory at
24 http://www.ethereal.com/appnotes/enpa-sa-00010.html
25
26 SOLUTION
27
28 It is recommended that all Gentoo Linux users who are running
29 net-analyzer/ethereal upgrade to ethereal as follows
30
31 emerge sync
32 emerge ethereal
33 emerge clean
34
35 - - - ---------------------------------------------------------------------
36 aliz@g.o - GnuPG key is available at http://cvs.gentoo.org/~aliz
37 - - - ---------------------------------------------------------------------
38 -----BEGIN PGP SIGNATURE-----
39 Version: GnuPG v1.2.2 (GNU/Linux)
40
41 iD8DBQE++iPvfT7nyhUpoZMRAvKBAKC3lQKGHRq0fGTEdpFcoP3JJcxjrgCdEbQ9
42 sUBm1GkCmTqjoIrZFHzJS3s=
43 =5vaU
44 -----END PGP SIGNATURE-----