Ethereal data parsing buffer overflow bug (Patch available)
26 Nov. 2000
Summary
Ethereal suffers from multiple remotely exploitable buffer overflows in its data parsing routines. An attacker can exploit those overflows by sending carefully crafted packets to a network that is being monitored by ethereal.
Vulnerable systems:
Ethereal 0.8.13
Debian GNU/Linux 2.2 alias potato
Conectiva Linux 5.0, 5.1
Immune systems:
Ethereal 0.8.14
Patch: Debian GNU/Linux 2.2 alias potato
Potato was released for Alpha, ARM, i386, M68k, PowerPC and Sparc. Packages for M68k are not available at this moment; when they become available they will be announced on http://security.debian.org/.