Ethereal: Multiple vulnerabilities Multiple vulnerabilities exist in Ethereal, which may allow an attacker to run arbitrary code or crash the program. ethereal 2005-03-12 2006-05-22 84547 remote 0.10.10 0.10.10

Ethereal is a feature rich network protocol analyzer.

There are multiple vulnerabilities in versions of Ethereal earlier than 0.10.10, including:

An attacker might be able to use these vulnerabilities to crash Ethereal and execute arbitrary code with the permissions of the user running Ethereal, which could be the root user.

For a temporary workaround you can disable all affected protocol dissectors. However, it is strongly recommended that you upgrade to the latest stable version.

All Ethereal users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/ethereal-0.10.10"
CAN-2005-0699 CAN-2005-0704 CAN-2005-0705 CAN-2005-0739 CVE-2005-0765 CVE-2005-0766 Ethereal enpa-sa-00018 jaervosz lewk