Published: 21-07-2006
Updated: 25-07-2006
Product:
Wireshark: Wireshark 0.99.1
Wireshark: Wireshark 0.99
Wireshark: Wireshark 0.10.13
Wireshark: Wireshark 0.10.4
Wireshark: Wireshark 0.10
Ethereal Group: Ethereal 0.10.5
Ethereal Group: Ethereal 0.10.4
Ethereal Group: Ethereal 0.10.3
Ethereal Group: Ethereal 0.10.2
Ethereal Group: Ethereal 0.10.14
Ethereal Group: Ethereal 0.10.13
Ethereal Group: Ethereal 0.10.12
Ethereal Group: Ethereal 0.10.11
Ethereal Group: Ethereal 0.10.10
Ethereal Group: Ethereal 0.10.1
Ethereal Group: Ethereal 0.10.0a
Ethereal Group: Ethereal 0.10.0
Ethereal Group: Ethereal 0.10
Severity: High (7.0)
CVSS vector: (AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Vulnerability type: Input validation error
Attack`s vector: Remotly exploitable
Potential loss type: Gain user access
Vulnerability description:
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
Patch available: Yes
Solution:
This vulnerability is addressed in the following product release:Ethereal Group, Ethereal, 0.99.2
References:
WIRESHARK: http://www.wireshark.org/security/wnpa-sec-2006-01.html
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/440576/100/0/threaded ...
MANDRIVA: http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:128
BID: http://www.securityfocus.com/bid/19051
FRSIRT: http://www.frsirt.com/english/advisories/2006/2850
SECUNIA: http://secunia.com/advisories/21078
SECUNIA: http://secunia.com/advisories/21107
