Name: Multiple problems in Ethereal versions 0.8.20 to 0.10.13
Docid: enpa-sa-00022
Date: December 27, 2005
Versions affected: 0.8.20 up to and including 0.10.13
Severity: High
Description:
Three security issues have turned up since Ethereal 0.10.13 was released:
The GTP dissector could go into an infinite loop.
Versions affected: 0.9.1 to 0.10.13.
iDefense found a buffer overflow in the OSPF dissector.
Versions affected: 0.8.20 to 0.10.13.
CVE: CAN-2005-3651
Impact:
It may be possible to make Ethereal crash, use up available system resources, or run arbitrary code by injecting a purposefully malformed packet onto the wire or by convincing someone to read a malformed trace file.
Resolution:
Upgrade to 0.10.14.
If you are running a version prior to 0.10.14 and you cannot upgrade, you can disable the GTP, IRC, and OSPF protocol dissectors by selecting Analyze->Enabled Protocols... and disabling them in the list.