存在问题:Ethereal 是用于监控网络流量的一个组件,在Ethereal 0.10.2的多个协议解析程序中存在漏洞。 操作平台: Ethereal 0.8.13 以后的版本,其中包括Ethereal 0.10.2 Red Hat Linux 9 Red Hat Linux AS, ES, WS (v. 2.1) and (v.3) Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor Mandrake 9.1, 9.2, 9.2/AMD64 漏洞危害:在以下的协议解析程序中,发现13个缓冲溢出:NetFlow, IGAP,EIGRP, PGM, IrDA,,BGP,ISUP, 和TCAP。同时,零长型的协议转换器会导致Ethereal攻击。小心制作的RADIUS包也可能产生攻击。另外,受损的滤色器文件也将导致分配错误。 解决方案:安装可用升级。 漏洞评估:高危。Ethereal以脚本的形式运行,可能会执行任意代码或产生攻击。 相关链接: http://www.ciac.org/ciac/bulletins/o-105.shtml http://www.ethereal.com/appnotes/enpa-sa-00013.html https://rhn.redhat.com/errata/RHSA-2004-137.html http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:024 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=