Oval Definition:oval:com.redhat.rhsa:def:20060602
Revision Date:2006-08-16Version:637
Title:RHSA-2006:0602: wireshark security update (was ethereal) (Moderate)
Description:Ethereal is a program for monitoring network traffic.

In May 2006, Ethereal changed its name to Wireshark. This update deprecates the Ethereal packages in Red Hat Enterprise Linux 2.1, 3, and 4 in favor of the supported Wireshark packages.

  • Several denial of service bugs were found in Ethereal's protocol dissectors. It was possible for Ethereal to crash or stop responding if it read a malformed packet off the network. (CVE-2006-3627, CVE-2006-3629, CVE-2006-3631)

  • Several buffer overflow bugs were found in Ethereal's ANSI MAP, NCP NMAS, and NDPStelnet dissectors. It was possible for Ethereal to crash or execute arbitrary code if it read a malformed packet off the network. (CVE-2006-3630, CVE-2006-3632)

  • Several format string bugs were found in Ethereal's Checkpoint FW-1, MQ, XML, and NTP dissectors. It was possible for Ethereal to crash or execute arbitrary code if it read a malformed packet off the network. (CVE-2006-3628)

    Users of Ethereal should upgrade to these updated packages containing Wireshark version 0.99.2, which is not vulnerable to these issues
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-3627
    CVE-2006-3628
    CVE-2006-3629
    CVE-2006-3630
    CVE-2006-3631
    CVE-2006-3632
    RHSA-2006:0602
    RHSA-2006:0602-01
    RHSA-2006:0602-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • wireshark is earlier than 0:0.99.2-EL3.1
  • AND wireshark is signed with Red Hat master key
  • wireshark-gnome is earlier than 0:0.99.2-EL3.1
  • AND wireshark-gnome is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • wireshark-gnome is earlier than 0:0.99.2-EL4.1
  • AND wireshark-gnome is signed with Red Hat master key
  • wireshark is earlier than 0:0.99.2-EL4.1
  • AND wireshark is signed with Red Hat master key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • wireshark is earlier than 0:0.99.2-EL3.1
  • AND wireshark is signed with Red Hat master key
  • wireshark-gnome is earlier than 0:0.99.2-EL3.1
  • AND wireshark-gnome is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • wireshark is earlier than 0:0.99.2-EL4.1
  • AND wireshark is signed with Red Hat master key
  • wireshark-gnome is earlier than 0:0.99.2-EL4.1
  • AND wireshark-gnome is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • wireshark is earlier than 0:0.99.2-EL4.1
  • AND wireshark is signed with Red Hat redhatrelease2 key
  • wireshark-gnome is earlier than 0:0.99.2-EL4.1
  • AND wireshark-gnome is signed with Red Hat redhatrelease2 key
  • BACK