Gentoo Archives: gentoo-dev

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-security@g.o, gentoo-user@g.o, gentoo-dev@g.o, gentoo-desktop@g.o, gentooppc-user@g.o, gentooppc-dev@g.o, gentoo-sparc@g.o, gentoo-announce@g.o
Subject: [gentoo-dev] GLSA: ethereal
Date: Fri, 30 Aug 2002 03:22:32
Message-Id: 200208301022.31059.aliz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT
6 - - --------------------------------------------------------------------
7
8 PACKAGE :ethereal
9 SUMMARY :buffer overflow
10 DATE :2002-08-30 07:30 UTC
11
12 - - --------------------------------------------------------------------
13
14 OVERVIEW
15
16 The ISIS protocol dissector in Ethereal 0.9.5 and earlier versions
17 is susceptible to a buffer overflow.
18
19 DETAIL
20
21 It may be possible to make Ethereal crash or hang by injecting a
22 purposefully malformed packet onto the wire, or by convincing someone
23 to read a malformed packet trace file. It may be possible to make
24 Ethereal run arbitrary code by exploiting the buffer and pointer problems.
25
26 The full advisory can be read at
27 http://www.ethereal.com/appnotes/enpa-sa-00006.html
28
29 SOLUTION
30
31 It is recommended that all Gentoo Linux users who are running
32 net-analyzer/ethereal-0.9.5-r2 and earlier update their systems
33 as follows:
34
35 emerge rsync
36 emerge ethereal
37 emerge clean
38
39 - - --------------------------------------------------------------------
40 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
41 - - --------------------------------------------------------------------
42 -----BEGIN PGP SIGNATURE-----
43 Version: GnuPG v1.0.7 (GNU/Linux)
44
45 iD8DBQE9bytFfT7nyhUpoZMRAoqRAJwMkA4erznbQZLJx0pH1mSEZpMvHQCdHTQq
46 LCL3ZApIaH7V669MrYLaHy8=
47 =RqOb
48 -----END PGP SIGNATURE-----