CVE-2005-0739
Ethereal 0.10.9 (Windows) - '3G-A11' Remote Buffer Overflow
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2005-03-12 First Exploit
- 2005-03-13 CVE Reserved
- 2005-03-13 CVE Published
- 2024-02-18 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-189: Numeric Errors
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707 | Url Repurposed | |
http://marc.info/?l=bugtraq&m=111066805726551&w=2 | Mailing List | |
http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05 | X_refsource_misc | |
http://www.securityfocus.com/bid/12762 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687 | Signature |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/874 | 2005-03-12 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2005/dsa-718 | 2024-02-14 | |
http://www.ethereal.com/appnotes/enpa-sa-00018.html | 2024-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | <= 0.10.9 Search vendor "Ethereal Group" for product "Ethereal" and version " <= 0.10.9" | - |
Affected
|