漏洞信息详情
Ethereal 多个缓冲区溢出漏洞
- CNNVD编号:CNNVD-200503-079
- 危害等级: 高危
- CVE编号:
CVE-2005-0699
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-03-08
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
redhat - 漏洞来源:
Both Leon Juranic … -
漏洞简介
Ethereal 0.10.9及更早版本的CDMA A11 (3G-A11)剖析器(packet-3g-a11.c)中的dissect_a11_radius函数存在多个缓冲区溢出,远程攻击者可以通过带有大量长度值的RADIUS身份验证包执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Ethereal Group Ethereal 0.10
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.1
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.2
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.3
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Fedora ethereal-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora ethereal-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora ethereal-debuginfo-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora ethereal-debuginfo-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora ethereal-gnome-0.10.10-1.FC2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora ethereal-gnome-0.10.10-1.FC2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
Fedora Legacy ethereal-0.10.13-1.FC2.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/ethereal-0.10.1 3-1.FC2.2.legacy.i386.rpm
Fedora Legacy ethereal-gnome-0.10.13-1.FC2.2.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/ethereal-gnome- 0.10.13-1.FC2.2.legacy.i386.rpm
Mandrake ethereal-0.10.10-0.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php
Mandrake ethereal-0.10.10-0.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Ethereal Group Ethereal 0.10.4
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.5
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
http://www.ethereal.com/distribution/buildbot-builds/ethereal-setup-0. 10.9-SVN-13681.exe
Ethereal Group Ethereal 0.10.6
Ethereal Group Ethereal 0.10.10
http://www.ethereal.com/download.html
Ethereal Group ethereal-0.10.9-SVN-13681.tar.gz
http://www.ethereal.com/distribution/buildbot-builds/ethereal-0.10.9-S VN-13681.tar.gz
Ethereal Group ethereal-setup-0.10.9-SVN-13681.exe
参考网址
来源: BID
名称: 12759
链接:http://www.securityfocus.com/bid/12759
来源: REDHAT
名称: RHSA-2005:306
链接:http://www.redhat.com/support/errata/RHSA-2005-306.html
来源: www.ethereal.com
链接:http://www.ethereal.com/appnotes/enpa-sa-00018.html
来源: GENTOO
名称: GLSA-200503-16
链接:http://security.gentoo.org/glsa/glsa-200503-16.xml
来源: BUGTRAQ
名称: 20050308 Ethereal remote buffer overflow
链接:http://www.securityfocus.com/archive/1/392659
来源: FEDORA
名称: FLSA-2006:152922
链接:http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
来源: MANDRAKE
名称: MDKSA-2005:053
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2005:053
来源: MISC
链接:http://security.lss.hr/en/index.php?page=details&ID=LSS-2005-03-04
来源: BUGTRAQ
名称: 20050314 Ethereal 0.10.9 and below remote root exploit
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=111083125521813&w=2
来源: BUGTRAQ
名称: 20050309 RE: Ethereal remote buffer overflow – addon
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=111038641832400&w=2