The GPRS-LLC dissector in Ethereal 0.10.7 through 0.10.9, with the "ignore cipher bit" option enabled. allows remote attackers to cause a denial of service (application crash).
Link | Tags |
---|---|
http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml | patch vendor advisory |
http://www.mandriva.com/security/advisories?name=MDKSA-2005:053 | vendor advisory |
http://www.ethereal.com/appnotes/enpa-sa-00018.html | url repurposed vendor advisory |
http://www.redhat.com/support/errata/RHSA-2005-306.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10565 | vdb entry signature |
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html | vendor advisory |
http://www.securityfocus.com/bid/12762 | vdb entry |