Navigation
Package name ethereal
Date December 14th, 2005
Advisory ID MDKSA-2005:227
Affected versions 2006.0

Problem Description

A stack-based buffer overflow was discovered in the OSPF dissector in
Ethereal. This could potentially be abused to allow remote attackers
to execute arbitrary code via crafted packets.

The updated packages have been patched to prevent this problem.

Updated Packages

Mandriva Linux 2006

 027fdd01892a957cbd51e12bfb67c5f8  2006.0/RPMS/ethereal-0.10.13-0.5.20060mdk.i586.rpm
 73193fe2d3878cecab885d8b6cd6a08a  2006.0/RPMS/ethereal-tools-0.10.13-0.5.20060mdk.i586.rpm
 2ec34afc4cdbd31bfa68640f13ff806e  2006.0/RPMS/libethereal0-0.10.13-0.5.20060mdk.i586.rpm
 5254cd0a674ed501d25ec42ee4191cf1  2006.0/RPMS/tethereal-0.10.13-0.5.20060mdk.i586.rpm
 a8c390894b8410e06b12d1f2049db2d6  2006.0/SRPMS/ethereal-0.10.13-0.5.20060mdk.src.rpm

Mandriva Linux 2006/X86_64

 09829fadefeb435e75aefa966b51cc56  x86_64/2006.0/RPMS/ethereal-0.10.13-0.5.20060mdk.x86_64.rpm
 5c0e3a206220014841a540e149fe96e0  x86_64/2006.0/RPMS/ethereal-tools-0.10.13-0.5.20060mdk.x86_64.rpm
 7ca64eb45c380c5eccec6d99e4ca9780  x86_64/2006.0/RPMS/lib64ethereal0-0.10.13-0.5.20060mdk.x86_64.rpm
 8510de1e6d3f38ed08d6f863d56c0ee9  x86_64/2006.0/RPMS/tethereal-0.10.13-0.5.20060mdk.x86_64.rpm
 a8c390894b8410e06b12d1f2049db2d6  x86_64/2006.0/SRPMS/ethereal-0.10.13-0.5.20060mdk.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3651

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

		rpm --checksig package.rpm
		

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.