Description: | Description:
The remote host is missing updates announced in advisory FLSA-2004:1193.
Ethereal is a network traffic analyzer for Unix-ish operating systems.
The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-1012 to this issue.
The Q.931 dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-1013 to this issue. Users of tcpdump should update to these update packages, which contain a backported security patch that corrects this issue.
Users of ethereal should update to these update packages, which contain a backported security patch that corrects this issue.
Fedora Legacy would like to thank Christian Pearce for providing a backported fix for Red Hat Linux 7.2, 7.3, and 8.0.
Affected platforms: Redhat 7.2 Redhat 7.3 Redhat 8
Solution: http://www.securityspace.com/smysecure/catid.html?in=FLSA-2004:1193 http://www.ethereal.com/appnotes/enpa-sa-00012.html
Risk factor : Critical
CVSS Score: 10.0
|