Vade79 has reported a vulnerability in Ethereal, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the decoding of the RSVP protocol and can be exploited via a specially crafted RSVP packet.
Successful exploitation causes Ethereal to enter an infinite loop and stop responding.
The vulnerability has been reported in version 0.10.10. Prior versions may also be affected.
SOFTWARE: Ethereal 0.x
SOLUTION: The vulnerability has reportedly been fixed in the CVS repository.
VERIFY ADVISORY: http://secunia.com/advisories/15144/
Secunia Security Advisories
|