Oval Definition:oval:com.redhat.rhsa:def:20050306
Revision Date:2005-03-18Version:502
Title:RHSA-2005:306: ethereal security update (Moderate)
Description:The ethereal package is a program for monitoring network traffic.



A number of security flaws have been discovered in Ethereal. On a system where Ethereal is running, a remote attacker could send malicious packets to trigger these flaws and cause Ethereal to crash or potentially execute arbitrary code.

A buffer overflow flaw was discovered in the Etheric dissector. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0704 to this issue.

The GPRS-LLC dissector could crash if the "ignore cipher bit" option was set. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0705 to this issue.

A buffer overflow flaw was discovered in the 3GPP2 A11 dissector. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0699 to this issue.

A buffer overflow flaw was discovered in the IAPP dissector. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0739 to this issue.

Users of ethereal should upgrade to these updated packages, which contain version 0.10.10 and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0699
CVE-2005-0704
CVE-2005-0705
CVE-2005-0739
CVE-2005-0765
CVE-2005-0766
RHSA-2005:306-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • ethereal-gnome is earlier than 0:0.10.10-1.EL3.1
  • AND ethereal-gnome is signed with Red Hat master key
  • ethereal is earlier than 0:0.10.10-1.EL3.1
  • AND ethereal is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • ethereal-gnome is earlier than 0:0.10.10-1.EL4.1
  • AND ethereal-gnome is signed with Red Hat master key
  • ethereal is earlier than 0:0.10.10-1.EL4.1
  • AND ethereal is signed with Red Hat master key
  • BACK