Multiple vulnerabilities have been identified in Ethereal, which could be exploited by attackers to cause a Denial of Service or execute arbitrary commands. These vulnerabilities exist due to various errors :
- The COPS dissector could go into an infinite loop.
- The DLSw dissector could cause an assertion, making Ethereal exit prematurely.
- The DNP dissector could cause memory corruption.
- The Gnutella dissector could cause an assertion, making Ethereal exit prematurely.
- The MMSE dissector could free static memory.
- The X11 protocol dissector is vulnerable to a string buffer overflow.
Credits
Vulnerability reported by Ethereal
ChangeLog
2005-01-21 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.