CVE-2005-3651 Information

Description

Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12 and possibly other versions allows remote attackers to execute arbitrary code via crafted packets.

Reference

ftp://patches.sgi.com/support/free/security/advisories/20060201-01-U http://anonsvn.ethereal.com/viewcvs/viewcvs.py/trunk/epan/dissectors/packet-ospf.c http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html http://secunia.com/advisories/17973 http://secunia.com/advisories/18012 http://secunia.com/advisories/18062 http://secunia.com/advisories/18331 http://secunia.com/advisories/18426 http://secunia.com/advisories/18911 http://secunia.com/advisories/19012 http://secunia.com/advisories/19230 http://securityreason.com/securityalert/247 http://securitytracker.com/id?1015337 http://www.debian.org/security/2005/dsa-920 http://www.ethereal.com/appnotes/enpa-sa-00022.html http://www.gentoo.org/security/en/glsa/glsa-200512-06.xml http://www.idefense.com/application/poi/display?id=349&type=vulnerabilities http://www.mandriva.com/security/advisories?name=MDKSA-2005:227 http://www.mandriva.com/security/advisories?name=MDKSA-2006:002 http://www.redhat.com/support/errata/RHSA-2006-0156.html http://www.securityfocus.com/bid/15794 http://www.vupen.com/english/advisories/2005/2830 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A11286

Share on: