Name: Potential issue with Ethereal 0.9.5
Docid: enpa-sa-00006
Date: August 20, 2002
Versions affected: 0.9.5 and earlier
Severity: High
Description:
The ISIS protocol dissector in Ethereal 0.9.5 and earlier versions is susceptible to a buffer overflow. In order to determine which version of Ethereal you have installed, do one of the following:
ethereal -vor
tethereal -v(the "v" is lowercase").
Impact:
It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.
Resolution:
Upgrade to 0.9.6.
If you are running a version prior to 0.9.6, you can disable the ISIS protocol dissector by selecting Edit->Protocols... and deselecting "isis" from the list.