Vulnerabilities > CVE-2004-1761 - Unspecified vulnerability in Ethereal Group Ethereal
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ethereal-group
nessus
Summary
Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file.
Vulnerable Configurations
Nessus
NASL family | Red Hat Local Security Checks |
NASL id | REDHAT-RHSA-2004-136.NASL |
description | Updated Ethereal packages that fix various security vulnerabilities are now available. Ethereal is a program for monitoring network traffic. Stefan Esser reported that Ethereal versions 0.10.1 and earlier contain stack overflows in the IGRP, PGM, Metflow, ISUP, TCAP, or IGAP dissectors. On a system where Ethereal is being run a remote attacker could send malicious packets that could cause Ethereal to crash or execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0176 to this issue. Jonathan Heussser discovered that a carefully-crafted RADIUS packet could cause a crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0365 to this issue. Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0367 to this issue. Users of Ethereal should upgrade to these updated packages, which contain a version of Ethereal that is not vulnerable to these issues. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12482 |
published | 2004-07-06 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/12482 |
title | RHEL 2.1 / 3 : ethereal (RHSA-2004:136) |
code |
|
Oval
accepted | 2013-04-29T04:00:20.746-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file. | ||||||||
family | unix | ||||||||
id | oval:org.mitre.oval:def:10013 | ||||||||
status | accepted | ||||||||
submitted | 2010-07-09T03:56:16-04:00 | ||||||||
title | Unknown vulnerability in Ethereal 0.8.13 to 0.10.2 allows attackers to cause a denial of service (segmentation fault) via a malformed color filter file. | ||||||||
version | 26 |
Redhat
advisories |
| ||||
rpms |
|
References
- http://secunia.com/advisories/11185
- http://secunia.com/advisories/11185
- http://www.ethereal.com/appnotes/enpa-sa-00013.html
- http://www.ethereal.com/appnotes/enpa-sa-00013.html
- http://www.kb.cert.org/vuls/id/695486
- http://www.kb.cert.org/vuls/id/695486
- http://www.redhat.com/support/errata/RHSA-2004-136.html
- http://www.redhat.com/support/errata/RHSA-2004-136.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15572
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15572
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10013
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10013