RHEL 2.1 / 3 : ethereal (RHSA-2004:136)

medium Nessus Plugin ID 12482

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

Updated Ethereal packages that fix various security vulnerabilities are now available.

Ethereal is a program for monitoring network traffic.

Stefan Esser reported that Ethereal versions 0.10.1 and earlier contain stack overflows in the IGRP, PGM, Metflow, ISUP, TCAP, or IGAP dissectors. On a system where Ethereal is being run a remote attacker could send malicious packets that could cause Ethereal to crash or execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0176 to this issue.

Jonathan Heussser discovered that a carefully-crafted RADIUS packet could cause a crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0365 to this issue.

Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0367 to this issue.

Users of Ethereal should upgrade to these updated packages, which contain a version of Ethereal that is not vulnerable to these issues.

Solution

Update the affected ethereal and / or ethereal-gnome packages.

See Also

https://access.redhat.com/security/cve/cve-2004-0176

https://access.redhat.com/security/cve/cve-2004-0365

https://access.redhat.com/security/cve/cve-2004-0367

https://access.redhat.com/security/cve/cve-2004-1761

http://ethereal.archive.sunet.se/appnotes/enpa-sa-00013.html

https://access.redhat.com/errata/RHSA-2004:136

Plugin Details

Severity: Medium

ID: 12482

File Name: redhat-RHSA-2004-136.nasl

Version: 1.27

Type: local

Agent: unix

Published: 7/6/2004

Updated: 1/14/2021

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:ethereal, p-cpe:/a:redhat:enterprise_linux:ethereal-gnome, cpe:/o:redhat:enterprise_linux:2.1, cpe:/o:redhat:enterprise_linux:3

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 3/30/2004

Vulnerability Publication Date: 5/4/2004

Reference Information

CVE: CVE-2004-0176, CVE-2004-0365, CVE-2004-0367, CVE-2004-1761

RHSA: 2004:136