Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2005:037 - Security Advisory
Issued:
2005-02-15
Updated:
2005-02-15

RHSA-2005:037 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

ethereal security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

Updated Ethereal packages that fix various security vulnerabilities are now
available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red Hat
Security Response Team.

Description

Ethereal is a program for monitoring network traffic.

A number of security flaws have been discovered in Ethereal. On a system
where Ethereal is running, a remote attacker could send malicious packets
to trigger these flaws.

A flaw in the DICOM dissector could cause a crash. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2004-1139 to this issue.

A invalid RTP timestamp could hang Ethereal and create a large temporary
file, possibly filling available disk space. (CAN-2004-1140)

The HTTP dissector could access previously-freed memory, causing a crash.
(CAN-2004-1141)

An improperly formatted SMB packet could make Ethereal hang, maximizing CPU
utilization. (CAN-2004-1142)

The COPS dissector could go into an infinite loop. (CAN-2005-0006)

The DLSw dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0007)

The DNP dissector could cause memory corruption. (CAN-2005-0008)

The Gnutella dissector could cause an assertion, making Ethereal exit
prematurely. (CAN-2005-0009)

The MMSE dissector could free static memory, causing a crash. (CAN-2005-0010)

The X11 protocol dissector is vulnerable to a string buffer overflow.
(CAN-2005-0084)

Users of Ethereal should upgrade to these updated packages which contain
version 0.10.9 that is not vulnerable to these issues.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Affected Products

  • Red Hat Enterprise Linux Server 4 x86_64
  • Red Hat Enterprise Linux Server 4 ia64
  • Red Hat Enterprise Linux Server 4 i386
  • Red Hat Enterprise Linux Workstation 4 x86_64
  • Red Hat Enterprise Linux Workstation 4 ia64
  • Red Hat Enterprise Linux Workstation 4 i386
  • Red Hat Enterprise Linux Desktop 4 x86_64
  • Red Hat Enterprise Linux Desktop 4 i386
  • Red Hat Enterprise Linux for IBM z Systems 4 s390x
  • Red Hat Enterprise Linux for IBM z Systems 4 s390
  • Red Hat Enterprise Linux for Power, big endian 4 ppc

Fixes

  • BZ - 144188 - CAN-2004-1139 Ethereal flaws (CAN-2004-1140 CAN-2004-1141 CAN-2004-1142)
  • BZ - 145483 - CAN-2005-0006 multiple ethereal issues (CAN-2005-0007 CAN-2005-0008 CAN-2005-0009 CAN-2005-0010 CAN-2005-0084)

CVEs

  • CVE-2004-1139
  • CVE-2004-1140
  • CVE-2004-1141
  • CVE-2004-1142
  • CVE-2005-0006
  • CVE-2005-0007
  • CVE-2005-0008
  • CVE-2005-0009
  • CVE-2005-0010
  • CVE-2005-0084

References

  • http://www.ethereal.com/appnotes/enpa-sa-00016.html
  • http://www.ethereal.com/appnotes/enpa-sa-00017.html
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 4

SRPM
ethereal-0.10.9-1.EL4.1.src.rpm SHA-256: 1618f41759ee8d9711d326eaaac2ee234283eb3dcf277963e6b64850ea7e7d56
x86_64
ethereal-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 3a00e5fc2d3b81112eacb9b3d419a7bdba695fc69b7fbc61ecc10bdb14395fe0
ethereal-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 3a00e5fc2d3b81112eacb9b3d419a7bdba695fc69b7fbc61ecc10bdb14395fe0
ethereal-gnome-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 91a6d0b52b450d7a1959347241a6f375a6e055a8d8c4c6d36be7f1b278b3400a
ethereal-gnome-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 91a6d0b52b450d7a1959347241a6f375a6e055a8d8c4c6d36be7f1b278b3400a
ia64
ethereal-0.10.9-1.EL4.1.ia64.rpm SHA-256: 636fa0d7042d02586bd36ba0985bfedf7f8289f16e5eb8531a4849046bf64a04
ethereal-0.10.9-1.EL4.1.ia64.rpm SHA-256: 636fa0d7042d02586bd36ba0985bfedf7f8289f16e5eb8531a4849046bf64a04
ethereal-gnome-0.10.9-1.EL4.1.ia64.rpm SHA-256: 14ecc5913a7c1a20977334a507f3d3fac0108d82dbbba952a9b3ea840b500b9c
ethereal-gnome-0.10.9-1.EL4.1.ia64.rpm SHA-256: 14ecc5913a7c1a20977334a507f3d3fac0108d82dbbba952a9b3ea840b500b9c
i386
ethereal-0.10.9-1.EL4.1.i386.rpm SHA-256: 0fec11eedc4a2834e6f2c29e73ccbecc828ac103428ee6be0e9755a357ff1783
ethereal-0.10.9-1.EL4.1.i386.rpm SHA-256: 0fec11eedc4a2834e6f2c29e73ccbecc828ac103428ee6be0e9755a357ff1783
ethereal-gnome-0.10.9-1.EL4.1.i386.rpm SHA-256: 95d6cc9873a76574757d445a8b8279778cd875a313e15b40b9307a567447353c
ethereal-gnome-0.10.9-1.EL4.1.i386.rpm SHA-256: 95d6cc9873a76574757d445a8b8279778cd875a313e15b40b9307a567447353c

Red Hat Enterprise Linux Workstation 4

SRPM
ethereal-0.10.9-1.EL4.1.src.rpm SHA-256: 1618f41759ee8d9711d326eaaac2ee234283eb3dcf277963e6b64850ea7e7d56
x86_64
ethereal-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 3a00e5fc2d3b81112eacb9b3d419a7bdba695fc69b7fbc61ecc10bdb14395fe0
ethereal-gnome-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 91a6d0b52b450d7a1959347241a6f375a6e055a8d8c4c6d36be7f1b278b3400a
ia64
ethereal-0.10.9-1.EL4.1.ia64.rpm SHA-256: 636fa0d7042d02586bd36ba0985bfedf7f8289f16e5eb8531a4849046bf64a04
ethereal-gnome-0.10.9-1.EL4.1.ia64.rpm SHA-256: 14ecc5913a7c1a20977334a507f3d3fac0108d82dbbba952a9b3ea840b500b9c
i386
ethereal-0.10.9-1.EL4.1.i386.rpm SHA-256: 0fec11eedc4a2834e6f2c29e73ccbecc828ac103428ee6be0e9755a357ff1783
ethereal-gnome-0.10.9-1.EL4.1.i386.rpm SHA-256: 95d6cc9873a76574757d445a8b8279778cd875a313e15b40b9307a567447353c

Red Hat Enterprise Linux Desktop 4

SRPM
ethereal-0.10.9-1.EL4.1.src.rpm SHA-256: 1618f41759ee8d9711d326eaaac2ee234283eb3dcf277963e6b64850ea7e7d56
x86_64
ethereal-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 3a00e5fc2d3b81112eacb9b3d419a7bdba695fc69b7fbc61ecc10bdb14395fe0
ethereal-gnome-0.10.9-1.EL4.1.x86_64.rpm SHA-256: 91a6d0b52b450d7a1959347241a6f375a6e055a8d8c4c6d36be7f1b278b3400a
i386
ethereal-0.10.9-1.EL4.1.i386.rpm SHA-256: 0fec11eedc4a2834e6f2c29e73ccbecc828ac103428ee6be0e9755a357ff1783
ethereal-gnome-0.10.9-1.EL4.1.i386.rpm SHA-256: 95d6cc9873a76574757d445a8b8279778cd875a313e15b40b9307a567447353c

Red Hat Enterprise Linux for IBM z Systems 4

SRPM
ethereal-0.10.9-1.EL4.1.src.rpm SHA-256: 1618f41759ee8d9711d326eaaac2ee234283eb3dcf277963e6b64850ea7e7d56
s390x
ethereal-0.10.9-1.EL4.1.s390x.rpm SHA-256: 1ee12ff7f44d5f5c17504c5ea84d5b91bc19a9ed94b6a0dda409d0eff97a331c
ethereal-gnome-0.10.9-1.EL4.1.s390x.rpm SHA-256: 90e2d1dea09ce80f3f0bba71e410e01d9d5f28118ed8d33c55d15cfbd7c3ae8a
s390
ethereal-0.10.9-1.EL4.1.s390.rpm SHA-256: cb30e69c1faa313853149d495e27a31bb611ae1966a14b240926bb2ad96656a0
ethereal-gnome-0.10.9-1.EL4.1.s390.rpm SHA-256: 86a6466f0fb75a4873afff332e761b8f2bb2d9846a894c367be0a7d831f8daa9

Red Hat Enterprise Linux for Power, big endian 4

SRPM
ethereal-0.10.9-1.EL4.1.src.rpm SHA-256: 1618f41759ee8d9711d326eaaac2ee234283eb3dcf277963e6b64850ea7e7d56
ppc
ethereal-0.10.9-1.EL4.1.ppc.rpm SHA-256: f24546832a87b696b8a5c0069916b771be47cf657b1bb4681ee3acb160ef06b5
ethereal-gnome-0.10.9-1.EL4.1.ppc.rpm SHA-256: c16c374b08855eb9b6eabdcc1d9db8f03110e6d40d6c48886ac68e1ddbf825e6

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility