GLSA-200510-25 : Ethereal: Multiple vulnerabilities in protocol dissectors
Critical Nessus Plugin ID 20118
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200510-25 (Ethereal: Multiple vulnerabilities in protocol dissectors)
There are numerous vulnerabilities in versions of Ethereal prior to 0.10.13, including:
The SLIM3 and AgentX dissectors could overflow a buffer (CVE-2005-3243).
iDEFENSE discovered a buffer overflow in the SRVLOC dissector (CVE-2005-3184).
Multiple potential crashes in many dissectors have been fixed, see References for further details.
Furthermore an infinite loop was discovered in the IRC protocol dissector of the 0.10.13 release (CVE-2005-3313).
An attacker might be able to use these vulnerabilities to crash Ethereal or execute arbitrary code with the permissions of the user running Ethereal, which could be the root user.
There is no known workaround at this time.
SolutionAll Ethereal users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-analyzer/ethereal-0.10.13-r1'