Ethereal SOCKS Dissector Format String Vulnerability

A format string vulnerability has been reported in some versions of the SOCKS dissector for Ethereal.

An attacker can exploit this vulnerability by connecting to a vulnerable SOCKS server and sending malicious format string specifiers to the SOCKS server. If Ethereal is being used as a security tool to monitor network packets, it is possible that sensitive memory may be corrupted.

This has been confirmed to result in a denial of service condition. Additionally, it may be possible to cause Ethereal to execute malicious attacker-supplied code.


Privacy Statement
Copyright 2010, SecurityFocus