ethereal-devel: A Network Traffic Analyser ---------------------------------------------------------------------- File: ethereal-devel-0.10.14-16.11.ppc.rpm Patchrpm: ethereal-devel-0.10.14-16.11.ppc.patch.rpm Version: 0.10.14-16.11 Size: 120 kB Patchsize: 14 kB Date: Thu 09 Nov 2006 18:37:51 CET Source: ethereal-0.10.14-16.11.src.rpm Security: Yes ---------------------------------------------------------------------- Description: Various problems have been fixed in the network analyzer Ethereal, most leading to crashes of the ethereal program. CVE-2006-5740: A unspecified vulnerability in the LDAP dissector could be used to crash Ethereal. CVE-2006-4574: A single \0 byte heap overflow was fixed in the MIME multipart dissector. Potential of exploitability is unknown, but considered low. CVE-2006-4805: A denial of service problem in the XOT dissector can cause it to take up huge amount of memory and crash ethereal. CVE-2006-5469: The WBXML dissector could be used to crash ethereal. CVE-2006-5468: A NULL pointer dereference in the HTTP dissector could crash ethereal.