Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.51339
Kategorie:Conectiva Local Security Checks
Titel:Conectiva Security Advisory CLA-2004:835
Zusammenfassung:NOSUMMARY
Beschreibung:Description:

The remote host is missing updates announced in
advisory CLA-2004:835.

Ethereal[1] is a powerful network traffic analyzer with a graphical
user interface (GUI).

This update fixes several vulnerabilities[2] in Ethereal:

CVE-2004-0176: Stefan Esser discovered thirteen buffer overflows in
the dissector of the NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, and
TCAP protocol dissectors[3].

CVE-2004-0365: Jonathan Heussser discovered a denial of service
vulnerability in the RADIUS protocol dissector[4].

CVE-2004-0367: A zero-length presentation protocol selector can be
exploited to cause a denial of service[5].

These vulnerabilities can be exploited by a attacker who is able to
insert crafted packets in the wire being monitored by ethereal or
make an user open a trace file with such packets inside. When reading
this data, Ethereal will crash (characterizing a denial of service
condition) or, in the case of the buffer overflow vulnerabilities,
may execute arbitrary code with the privileges of the user running it
(usually root).


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.ethereal.com/
http://www.ethereal.com/appnotes/enpa-sa-00013.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367
http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:835
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : Medium

CVSS Score:
5.0

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2004-0176
Bugtraq: 20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows (Google Search)
http://marc.info/?l=bugtraq&m=108007072215742&w=2
Bugtraq: 20040329 LNSA-#2004-0007: Multiple security problems in Ethereal (Google Search)
http://marc.info/?l=bugtraq&m=108058005324316&w=2
Bugtraq: 20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal) (Google Search)
http://marc.info/?l=bugtraq&m=108213710306260&w=2
CERT/CC vulnerability note: VU#119876
http://www.kb.cert.org/vuls/id/119876
CERT/CC vulnerability note: VU#125156
http://www.kb.cert.org/vuls/id/125156
CERT/CC vulnerability note: VU#433596
http://www.kb.cert.org/vuls/id/433596
CERT/CC vulnerability note: VU#591820
http://www.kb.cert.org/vuls/id/591820
CERT/CC vulnerability note: VU#644886
http://www.kb.cert.org/vuls/id/644886
CERT/CC vulnerability note: VU#659140
http://www.kb.cert.org/vuls/id/659140
CERT/CC vulnerability note: VU#740188
http://www.kb.cert.org/vuls/id/740188
CERT/CC vulnerability note: VU#864884
http://www.kb.cert.org/vuls/id/864884
CERT/CC vulnerability note: VU#931588
http://www.kb.cert.org/vuls/id/931588
Conectiva Linux advisory: CLA-2004:835
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
Debian Security Information: DSA-511 (Google Search)
http://www.debian.org/security/2004/dsa-511
http://security.gentoo.org/glsa/glsa-200403-07.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
http://security.e-matters.de/advisories/032004.html
http://www.osvdb.org/6893
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10187
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A878
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A887
http://www.redhat.com/support/errata/RHSA-2004-136.html
http://www.redhat.com/support/errata/RHSA-2004-137.html
http://secunia.com/advisories/11185
XForce ISS Database: ethereal-multiple-dissectors-bo(15569)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15569
Common Vulnerability Exposure (CVE) ID: CVE-2004-0365
CERT/CC vulnerability note: VU#124454
http://www.kb.cert.org/vuls/id/124454
http://marc.info/?l=ethereal-dev&m=107962966700423&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A879
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A891
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9196
XForce ISS Database: ethereal-radius-dos(15571)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15571
Common Vulnerability Exposure (CVE) ID: CVE-2004-0367
CERT/CC vulnerability note: VU#792286
http://www.kb.cert.org/vuls/id/792286
http://www.ethereal.com/lists/ethereal-dev/200404/msg00296.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11071
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A880
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A905
XForce ISS Database: ethereal-zero-presentation-dos(15570)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15570
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.