Package: ethereal
Version: 0.10.11
Severity: grave
Justification: user security hole

Multiple problems in Ethereal's protocol dissectors have been
discovered.   It may be possible to make Ethereal crash, use up
available memory, or run arbitrary code by injecting a purposefully
malformed packet onto the wire or by convincing someone to read a
malformed packet trace file.

Versions affected: 0.8.5 up to and including 0.10.11

There is an advisory at
http://www.ethereal.com/appnotes/enpa-sa-00020.html



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to