Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ethereal | Ethereal_group | 0.10.3 (including) | 0.10.3 (including) |
Ethereal | Ethereal_group | 0.10.4 (including) | 0.10.4 (including) |
Ethereal | Ethereal_group | 0.10.5 (including) | 0.10.5 (including) |
Ethereal | Ethereal_group | 0.10.6 (including) | 0.10.6 (including) |
Ethereal | Ethereal_group | 0.10.7 (including) | 0.10.7 (including) |
Ethereal | Ethereal_group | 0.10.8 (including) | 0.10.8 (including) |
Ethereal | Ethereal_group | 0.10.9 (including) | 0.10.9 (including) |
Linux | Conectiva | 9.0 (including) | 9.0 (including) |
Linux | Conectiva | 10.0 (including) | 10.0 (including) |
Red Hat Enterprise Linux 3 | RedHat | ethereal-0:0.10.10-1.EL3.1 | * |
Ethereal | Ubuntu | dapper | * |
Wireshark | Ubuntu | devel | * |
Wireshark | Ubuntu | edgy | * |
Wireshark | Ubuntu | feisty | * |