Description
The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
Affected products
- ethereal_group / ethereal0.9.15 – 0.9.15
- ethereal_group / ethereal0.10.4 – 0.10.4
- gentoo / linux
- mandrakesoft / mandrake_linux9.2 – 9.2
- mandrakesoft / mandrake_linux10.0 – 10.0
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux2.1 – 2.1
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / enterprise_linux3.0 – 3.0
- RedHat / linux_advanced_workstation2.1 – 2.1
References
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10252
- MISChttp://securitytracker.com/id?1010655
- MISChttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000916
- VENDOR_ADVISORYhttp://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:067
- MISChttp://www.ethereal.com/appnotes/enpa-sa-00015.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/12024
- MISChttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=127381
- MISChttp://www.redhat.com/archives/fedora-announce-list/2004-July/msg00013.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/16631
- MISChttp://www.kb.cert.org/vuls/id/518782
- MISChttp://www.redhat.com/archives/fedora-announce-list/2004-July/msg00014.html
- MISChttp://www.redhat.com/support/errata/RHSA-2004-378.html
- MISChttp://www.gentoo.org/security/en/glsa/glsa-200407-08.xml