Description
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
Affected products
- ethereal_group / ethereal0.8.15 – 0.8.15
- ethereal_group / ethereal0.8.16 – 0.8.16
- ethereal_group / ethereal0.8.17 – 0.8.17
- ethereal_group / ethereal0.8.18 – 0.8.18
- ethereal_group / ethereal0.8.19 – 0.8.19
- ethereal_group / ethereal0.9 – 0.9
- ethereal_group / ethereal0.9.1 – 0.9.1
- ethereal_group / ethereal0.9.2 – 0.9.2
- ethereal_group / ethereal0.9.3 – 0.9.3
- ethereal_group / ethereal0.9.4 – 0.9.4
- ethereal_group / ethereal0.9.5 – 0.9.5
- ethereal_group / ethereal0.9.6 – 0.9.6
- ethereal_group / ethereal0.9.7 – 0.9.7
- ethereal_group / ethereal0.9.8 – 0.9.8
- ethereal_group / ethereal0.9.9 – 0.9.9
- ethereal_group / ethereal0.9.10 – 0.9.10
- ethereal_group / ethereal0.9.11 – 0.9.11
- ethereal_group / ethereal0.9.12 – 0.9.12
- ethereal_group / ethereal0.9.13 – 0.9.13
- ethereal_group / ethereal0.9.14 – 0.9.14
- ethereal_group / ethereal0.9.15 – 0.9.15
- ethereal_group / ethereal0.9.16 – 0.9.16
- ethereal_group / ethereal0.10 – 0.10
- ethereal_group / ethereal0.10.1 – 0.10.1
- ethereal_group / ethereal0.10.2 – 0.10.2
- ethereal_group / ethereal0.10.3 – 0.10.3
- ethereal_group / ethereal0.10.4 – 0.10.4
- gentoo / linux
- mandrakesoft / mandrake_linux9.2 – 9.2
- mandrakesoft / mandrake_linux10.0 – 10.0
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / linux_advanced_workstation2.1 – 2.1
References
- MISChttp://securitytracker.com/id?1010655
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000916
- VENDOR_ADVISORYhttp://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067
- MISChttp://www.ethereal.com/appnotes/enpa-sa-00015.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/12024
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9721
- MISChttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381
- MISChttp://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/16632
- MISChttp://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2004/dsa-528
- MISChttp://www.kb.cert.org/vuls/id/835846
- MISChttp://www.redhat.com/support/errata/RHSA-2004-378.html
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200407-08.xml