Name: Multiple problems in Ethereal 0.10.4
Docid: enpa-sa-00015
Date: July 6, 2004
Versions affected: 0.8.15 up to and including 0.10.4
Severity: High
Description:
Issues have been discovered in the following protocol dissectors:
Impact:
It may be possible to make Ethereal crash or run arbitrary code by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Resolution:
Upgrade to 0.10.5.
If you are running a version prior to 0.10.5 and you cannot upgrade, you can disable all of the protocol dissectors listed above by selecting Analyze->Enabled Protocols... and deselecting them from the list. For SMB, you can alternatively disable SID snooping in the SMB protocol preferences. However, it is strongly recommended that you upgrade to 0.10.5.