Red Hat alert: Updated Ethereal packages fix security issues

Posted by dave on Jan 5, 2004 7:51 AM EDT
Mailing list
Mail this story
Print this story

Updated Ethereal packages that fix two security vulnerabilities are now available.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------- Red Hat Security Advisory

Synopsis: Updated Ethereal packages fix security issues Advisory ID: RHSA-2004:002-01 Issue date: 2004-01-05 Updated on: 2004-01-05 Product: Red Hat Enterprise Linux Keywords: Cross references: Obsoletes: RHSA-2003:324 CVE Names: CAN-2003-1012 CAN-2003-1013 - ---------------------------------------------------------------------

1. Topic:

Updated Ethereal packages that fix two security vulnerabilities are now available.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 3 - i386 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64

3. Problem description:

Ethereal is a program for monitoring network traffic.

Two security issues have been found that affect Ethereal. By exploiting these issues it may be possible to make Ethereal crash by injecting an intentionally malformed packet onto the wire or by convincing someone to read a malformed packet trace file. It is not known if these issues could allow arbitrary code execution.

The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-1012 to this issue.

The Q.931 dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-1013 to this issue.

Users of Ethereal should update to these erratum packages containing Ethereal version 0.10.0, which is not vulnerable to these issues.

4. Solution:

Before applying this update, make sure all previously released errata relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. Bug IDs fixed (http://bugzilla.redhat.com/bugzilla for more info):

112224 - CAN-2003-1012/3 Ethereal security issues

6. RPMs required:

Red Hat Enterprise Linux AS (Advanced Server) version 2.1:

SRPMS: ftp://updates.redhat.com/enterprise/2.1AS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm

ia64: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm

Red Hat Linux Advanced Workstation 2.1:

SRPMS: ftp://updates.redhat.com/enterprise/2.1AW/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm

ia64: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.ia64.rpm

Red Hat Enterprise Linux ES version 2.1:

SRPMS: ftp://updates.redhat.com/enterprise/2.1ES/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm

Red Hat Enterprise Linux WS version 2.1:

SRPMS: ftp://updates.redhat.com/enterprise/2.1WS/en/os/SRPMS/ethereal-0.10.0a-0.AS21.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.AS21.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.AS21.1.i386.rpm

Red Hat Enterprise Linux AS version 3:

SRPMS: ftp://updates.redhat.com/enterprise/3AS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.i386.rpm

ia64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.ia64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.ia64.rpm

ppc: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.ppc.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.ppc.rpm

s390: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.s390.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.s390.rpm

s390x: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.s390x.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.s390x.rpm

x86_64: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.x86_64.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.x86_64.rpm

Red Hat Enterprise Linux ES version 3:

SRPMS: ftp://updates.redhat.com/enterprise/3ES/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i386.rpm Available from Red Hat Network: ethereal-gnome-0.10.0a-0.30E.1.i386.rpm

Red Hat Enterprise Linux WS version 3:

SRPMS: ftp://updates.redhat.com/enterprise/3WS/en/os/SRPMS/ethereal-0.10.0a-0.30E.1.src.rpm

i386: Available from Red Hat Network: ethereal-0.10.0a-0.30E.1.i38



  Nav
» Read more about: Story Type: Security; Groups: Red Hat

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.