Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Red Hat Local Security Checks >> RHSA-2005-011: ethereal


Vulnerability Assessment Details

RHSA-2005-011: ethereal

Vulnerability Assessment Summary
Check for the version of the ethereal packages

Detailed Explanation for this Vulnerability Assessment


Updated Ethereal packages that fix various security vulnerabilities are now
available.

Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CVE-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CVE-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CVE-2004-1142)

The COPS dissector could go into an infinite loop. (CVE-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CVE-2005-0007)

The DNP dissector could cause memory corruption. (CVE-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CVE-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CVE-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CVE-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.




Solution : http://rhn.redhat.com/errata/RHSA-2005-011.html
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors


Lenovo ThinkPad E14 Gen 2 Laptop 14” HD Ryzen 5 16GB RAM 512GB SSD Win 11 Pro picture

Lenovo ThinkPad E14 Gen 2 Laptop 14” HD Ryzen 5 16GB RAM 512GB SSD Win 11 Pro

$334.99



Lenovo ThinkPad E14 Gen 3 Laptop 14” FHD AMD Ryzen 5 16GB RAM 512GB SSD Win 11 picture

Lenovo ThinkPad E14 Gen 3 Laptop 14” FHD AMD Ryzen 5 16GB RAM 512GB SSD Win 11

$374.99



Lenovo Thinkbook 14s Yoga ITL 14” Core i7-1165G7, 16GB RAM, 512GB SSD Touch picture

Lenovo Thinkbook 14s Yoga ITL 14” Core i7-1165G7, 16GB RAM, 512GB SSD Touch

$379.00



Lenovo ThinkPad L15 Gen 3 15.6

Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black

$241.50



Lenovo IdeaPad Slim 3x 15Q8X10 83N30010US 16GB 1TB SSD keybord Parts/Repair picture

Lenovo IdeaPad Slim 3x 15Q8X10 83N30010US 16GB 1TB SSD keybord Parts/Repair

$190.00



Lenovo Legion 5 Gaming 15.1

Lenovo Legion 5 Gaming 15.1" WQXGA OLED 165Hz Core i9-14900HX 16GB 1TB RTX 5070

$1469.00



Lenovo ThinkPad T14 Gen 1 14

Lenovo ThinkPad T14 Gen 1 14" AMD Ryzen 5 16GB 256GB SSD

$219.99



Lenovo ThinkPad X13 Gen 1 i5-10310U 16GB 512GB SSD Touch Win 11 Pro Good picture

Lenovo ThinkPad X13 Gen 1 i5-10310U 16GB 512GB SSD Touch Win 11 Pro Good

$222.99



Lenovo ThinkPad L15 Gen 3 15.6

Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black

$241.50



Lenovo ThinkPad T14s Laptop 14” Laptop Core i5 8GB RAM 256GB SSD Windows 11 Pro picture

Lenovo ThinkPad T14s Laptop 14” Laptop Core i5 8GB RAM 256GB SSD Windows 11 Pro

$249.99



Discussions

No Discussions have been posted on this vulnerability.