Published: 21-07-2006
Updated: 26-02-2008
Product:
Ethereal Group: Ethereal 0.99.0
Ethereal Group: Ethereal 0.10.9
Ethereal Group: Ethereal 0.10.8
Ethereal Group: Ethereal 0.10.7
Ethereal Group: Ethereal 0.10.6
Ethereal Group: Ethereal 0.10.5
Ethereal Group: Ethereal 0.10.4
Ethereal Group: Ethereal 0.10.3
Ethereal Group: Ethereal 0.10.2
Ethereal Group: Ethereal 0.10.14
Ethereal Group: Ethereal 0.10.13
Ethereal Group: Ethereal 0.10.12
Ethereal Group: Ethereal 0.10.11
Ethereal Group: Ethereal 0.10.10
Ethereal Group: Ethereal 0.10.1
Ethereal Group: Ethereal 0.10.0a
Ethereal Group: Ethereal 0.10.0
Ethereal Group: Ethereal 0.10
Ethereal Group: Ethereal 0.9.16
Ethereal Group: Ethereal 0.9.15
Ethereal Group: Ethereal 0.9.14
Ethereal Group: Ethereal 0.9.13
Ethereal Group: Ethereal 0.9.12
Ethereal Group: Ethereal 0.9.11
Ethereal Group: Ethereal 0.9.10
Ethereal Group: Ethereal 0.9.9
Ethereal Group: Ethereal 0.9.8
Ethereal Group: Ethereal 0.9.7
Ethereal Group: Ethereal 0.9.6
Ethereal Group: Ethereal 0.9.5
Ethereal Group: Ethereal 0.9.4
Ethereal Group: Ethereal 0.9.3
Ethereal Group: Ethereal 0.9.2
Ethereal Group: Ethereal 0.9.1
Ethereal Group: Ethereal 0.9.0
Ethereal Group: Ethereal 0.8.20
Ethereal Group: Ethereal 0.8.19
Ethereal Group: Ethereal 0.8.18
Ethereal Group: Ethereal 0.8.17a
Ethereal Group: Ethereal 0.8.17
Ethereal Group: Ethereal 0.8.16
Severity: High (7.5)
CVSS vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Vulnerability type: Buffer overflow
Potential loss type: Gain user access, Integrity, Confidentiality, Availability
Vulnerability description:
Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.
Patch available: Yes
Solution:
This vulnerability is addressed in the following product release:Ethereal Group, Ethereal, 0.99.2
References:
WIRESHARK: http://www.wireshark.org/security/wnpa-sec-2006-01.html
BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/440576/100/0/threaded ...
MANDRIVA: http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:128
BID: http://www.securityfocus.com/bid/19051
FRSIRT: http://www.frsirt.com/english/advisories/2006/2850
SECUNIA: http://secunia.com/advisories/21078
SECUNIA: http://secunia.com/advisories/21107
GENTOO: http://security.gentoo.org/glsa/glsa-200607-09.xml
SECUNIA: http://secunia.com/advisories/21121
SECUNIA: http://secunia.com/advisories/21204
https://issues.rpath.com/browse/RPL-512
DEBIAN: http://www.debian.org/security/2006/dsa-1127
SECTRACK: http://securitytracker.com/id?1016532
SECUNIA: http://secunia.com/advisories/21249
REDHAT: http://rhn.redhat.com/errata/RHSA-2006-0602.html
SUSE: http://www.novell.com/linux/security/advisories/2006_20_sr.html
SECUNIA: http://secunia.com/advisories/21488
SGI: ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
SECUNIA: http://secunia.com/advisories/21598
http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm
SECUNIA: http://secunia.com/advisories/22089
SECUNIA: http://secunia.com/advisories/21467
XF: http://xforce.iss.net/xforce/xfdb/27830
MANDRIVA: http://www.mandriva.com/security/advisories?name=MDKSA-2006:128
OSVDB: http://www.osvdb.org/27371
