Published: 21-07-2006
Updated: 27-06-2007
Product:
Ethereal Group: Ethereal 0.99.0
Ethereal Group: Ethereal 0.10.9
Ethereal Group: Ethereal 0.10.8
Ethereal Group: Ethereal 0.10.7
Ethereal Group: Ethereal 0.10.6
Ethereal Group: Ethereal 0.10.5
Ethereal Group: Ethereal 0.10.4
Ethereal Group: Ethereal 0.10.3
Ethereal Group: Ethereal 0.10.2
Ethereal Group: Ethereal 0.10.14
Ethereal Group: Ethereal 0.10.13
Ethereal Group: Ethereal 0.10.12
Ethereal Group: Ethereal 0.10.11
Ethereal Group: Ethereal 0.10.10
Ethereal Group: Ethereal 0.10.1
Ethereal Group: Ethereal 0.10.0a
Ethereal Group: Ethereal 0.10.0
Ethereal Group: Ethereal 0.10
Ethereal Group: Ethereal 0.9.16
Ethereal Group: Ethereal 0.9.15
Ethereal Group: Ethereal 0.9.14
Ethereal Group: Ethereal 0.9.13
Ethereal Group: Ethereal 0.9.12
Ethereal Group: Ethereal 0.9.11
Ethereal Group: Ethereal 0.9.10
Severity: Low (2.3)
CVSS vector: (AV:R/AC:L/Au:NR/C:N/I:N/A:P/B:N)
Potential loss type: Availability
Vulnerability description:
Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
Patch available: Yes
Solution:
This vulnerability is addressed in the following product release:Ethereal Group, Ethereal, 0.99.2
References:
WIRESHARK: http://www.wireshark.org/security/wnpa-sec-2006-01.html
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/440576/100/0/threaded ...
MANDRIVA: http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:128
BID: http://www.securityfocus.com/bid/19051
FRSIRT: http://www.frsirt.com/english/advisories/2006/2850
SECUNIA: http://secunia.com/advisories/21078
SECUNIA: http://secunia.com/advisories/21107
GENTOO: http://security.gentoo.org/glsa/glsa-200607-09.xml
SECUNIA: http://secunia.com/advisories/21121
SECUNIA: http://secunia.com/advisories/21204
DEBIAN: http://www.debian.org/security/2006/dsa-1127
SECTRACK: http://securitytracker.com/id?1016532
SECUNIA: http://secunia.com/advisories/21249
REDHAT: http://rhn.redhat.com/errata/RHSA-2006-0602.html
SUSE: http://www.novell.com/linux/security/advisories/2006_20_sr.html
SECUNIA: http://secunia.com/advisories/21488
SGI: ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
SECUNIA: http://secunia.com/advisories/21598
http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm
SECUNIA: http://secunia.com/advisories/22089
SECUNIA: http://secunia.com/advisories/21467
XF: http://xforce.iss.net/xforce/xfdb/27829
