Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200604-17 ] Ethereal: Multiple vulnerabilities in protocol dissectors
Date: Thu, 27 Apr 2006 05:39:42
Message-Id: 200604270717.01443.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200604-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Ethereal: Multiple vulnerabilities in protocol dissectors
9 Date: April 27, 2006
10 Bugs: #130505
11 ID: 200604-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Ethereal is vulnerable to numerous vulnerabilities, potentially
19 resulting in the execution of arbitrary code.
20
21 Background
22 ==========
23
24 Ethereal is a feature-rich network protocol analyzer.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-analyzer/ethereal < 0.99.0 >= 0.99.0
33
34 Description
35 ===========
36
37 Coverity discovered numerous vulnerabilities in versions of Ethereal
38 prior to 0.99.0, including:
39
40 * buffer overflows in the ALCAP (CVE-2006-1934), COPS (CVE-2006-1935)
41 and telnet (CVE-2006-1936) dissectors.
42
43 * buffer overflows in the NetXray/Windows Sniffer and Network
44 Instruments file code (CVE-2006-1934).
45
46 For further details please consult the references below.
47
48 Impact
49 ======
50
51 An attacker might be able to exploit these vulnerabilities to crash
52 Ethereal or execute arbitrary code with the permissions of the user
53 running Ethereal, which could be the root user.
54
55 Workaround
56 ==========
57
58 There is no known workaround at this time.
59
60 Resolution
61 ==========
62
63 All Ethereal users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=net-analyzer/ethereal-0.99.0"
67
68 References
69 ==========
70
71 [ 1 ] CVE-2006-1932
72 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932
73 [ 2 ] CVE-2006-1933
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1933
75 [ 3 ] CVE-2006-1934
76 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1934
77 [ 4 ] CVE-2006-1935
78 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1935
79 [ 5 ] CVE-2006-1936
80 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1936
81 [ 6 ] CVE-2006-1937
82 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1937
83 [ 7 ] CVE-2006-1938
84 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938
85 [ 8 ] CVE-2006-1939
86 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1939
87 [ 9 ] CVE-2006-1940
88 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1940
89 [ 10 ] Ethereal enpa-sa-00023
90 http://www.ethereal.com/appnotes/enpa-sa-00023.html
91
92 Availability
93 ============
94
95 This GLSA and any updates to it are available for viewing at
96 the Gentoo Security Website:
97
98 http://security.gentoo.org/glsa/glsa-200604-17.xml
99
100 Concerns?
101 =========
102
103 Security is a primary focus of Gentoo Linux and ensuring the
104 confidentiality and security of our users machines is of utmost
105 importance to us. Any security concerns should be addressed to
106 security@g.o or alternatively, you may file a bug at
107 http://bugs.gentoo.org.
108
109 License
110 =======
111
112 Copyright 2006 Gentoo Foundation, Inc; referenced text
113 belongs to its owner(s).
114
115 The contents of this document are licensed under the
116 Creative Commons - Attribution / Share Alike license.
117
118 http://creativecommons.org/licenses/by-sa/2.0