Ethereal

enpa-sa-00010
Google
 
Web Ethereal.com

Home | Introduction | Download | Documentation | Lists | FAQ | Development | Wiki | Bugs

Summary

Name: Several security problems in Ethereal 0.9.12

Docid: enpa-sa-00010

Date: June 11, 2003

Versions affected: unknown up to 0.9.12

Severity: High

Details

Description:

Further source code auditing by Timo Sirainen has turned up several string handling flaws in various protocol dissectors. Separate security problems were discovered by other people:

Impact:

It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file.

Resolution:

Upgrade to 0.9.13.