[SECURITY] Fedora Core 2 Update: ethereal-0.10.3-2.1

Phil Knirsch pknirsch at redhat.com
Thu Jun 3 16:02:32 UTC 2004

Fedora Update Notification

Product     : Fedora Core 2
Name        : ethereal
Version     : 0.10.3
Release     : 2.1
Summary     : Network traffic analyzer
Description :
Ethereal is a network traffic analyzer for Unix-ish operating systems.

This package lays base for libpcap, a packet capture and filtering
library, contains command-line utilities, contains plugins and
documentation for ethereal. A graphical user interface is packaged
separately to GTK+ package.

Update Information:

  Issues have been discovered in the following protocol dissectors:

     * A SIP packet could make Ethereal crash under specific conditions, 
as described in the following message:
     * The AIM dissector could throw an assertion, causing Ethereal to 
terminate abnormally (0.10.3).
     * It was possible for the SPNEGO dissector to dereference a null 
pointer, causing a crash (0.9.8 to 0.10.3).
     * The MMSE dissector was susceptible to a buffer overflow. (0.10.1 
to 0.10.3).

All users of the Ethereal package are strongly encouraged to update to these
latest packages.

* Tue Jun 01 2004 Phil Knirsch <pknirsch at redhat.com> 0.10.3-2.1

- Included backported security fixes from ethereal-0.10.4

This update can be downloaded from:

047f4b58fc2ce78dff5f7f27d588faa7  SRPMS/ethereal-0.10.3-2.1.src.rpm
c5954b26aa5e448eb7a1ad1d9ac08692  i386/ethereal-0.10.3-2.1.i386.rpm
052063b1167471b6fcedfa7222a2fc4c  i386/ethereal-gnome-0.10.3-2.1.i386.rpm
efdd124a1b6cdbd61d13ddadb1b0ec28  x86_64/ethereal-0.10.3-2.1.x86_64.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.

Philipp Knirsch      | Tel.:  +49-711-96437-470
Development          | Fax.:  +49-711-96437-111
Red Hat GmbH         | Email: Phil Knirsch <phil at redhat.de>
Hauptstaetterstr. 58 | Web:   http://www.redhat.de/
D-70178 Stuttgart
Motd:  You're only jealous cos the little penguins are talking to me.

More information about the announce mailing list