P-260: Ethereal 0.10.12 Released Privacy and Legal Notice

CIAC INFORMATION BULLETIN

P-260: Ethereal 0.10.12 Released

[Ethereal Document ID: enpa-sa-00020]

July 27, 2005 17:00 GMT

PROBLEM: Several security issues have been addressed in the 0.10.12 release of Ethereal. Ethereal is a widely used open source network protocol analyzer.
PLATFORM: Ethereal versions 0.8.5 up to and including 0.10.11
DAMAGE: It may be possible to make Ethereal crash, use up available memory, or run arbitrary code by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
SOLUTION: Apply the security updates.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. Exploiting the vulnerabilities may cause Ethereal to crash, use up memory, or run arbitrary code by injecting a carefully crafted malformed packet onto the wire. Ethereal is typically invoked by the root user.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/p-260.shtml
  ORIGINAL BULLETIN: http://www.ethereal.com/appnotes/enpa-sa-00020.html

[***** Start Ethereal Document ID:  enpa-sa-00020 *****]


Summary

Name: Multiple problems in Ethereal versions 0.8.5 to 0.10.10

Docid: enpa-sa-00020

Date: July 26, 2005

Versions affected: 0.8.5 up to and including 0.10.11

Severity: High

Details

Description:

Our testing program has turned up several more security issues:

Steve Grubb at Red Hat found the following issues: iDEFENSE found the following issues: Ethereal uses the zlib compression library. Security vulnerabilities have been discovered in zlib 1.2.1 and 1.2.2. The Windows installer now ships with zlib 1.2.3, which fixes these vulnerabilities.

Impact:

It may be possible to make Ethereal crash, use up available memory, or run arbitrary code by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed packet trace file.

Resolution:

Upgrade to 0.10.12. Due to the severity and scope of the defects that have been discovered, no workaround is available.


[***** End Ethereal Document ID:  enpa-sa-00020 *****]

   

CIAC wishes to acknowledge the contributions of Ethereal for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/