CVE-2006-3628
rPSA-2006-0132-1.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
Múltiples vulnerabilidades de formato de cadena en Wireshark (atmbién conocido como Ethereal) 0.10.x a 0.99.0 permite a atacantes remotos provocar denegación de servicio y posiblemente ejecutar código de su eleccción a través de los disectores (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, y (5) NTP.
All versions of the ethereal and tethereal packages contain vulnerabilities in packet dissector modules, which may allow various attacks including subverting the user who is running ethereal. Since ethereal is generally run as root to view network traffic directly, this may allow complete access to the vulnerable system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-17 CVE Reserved
- 2006-07-18 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (34)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1016532 | Vdb Entry | |
http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm | X_refsource_confirm | |
http://www.osvdb.org/27362 | Vdb Entry | |
http://www.osvdb.org/27363 | Vdb Entry | |
http://www.osvdb.org/27364 | Vdb Entry | |
http://www.osvdb.org/27369 | Vdb Entry | |
http://www.securityfocus.com/archive/1/440576/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27822 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27823 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27824 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27825 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27828 | Vdb Entry | |
https://issues.rpath.com/browse/RPL-512 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9175 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/21078 | 2018-10-18 | |
http://secunia.com/advisories/21107 | 2018-10-18 | |
http://www.securityfocus.com/bid/19051 | 2018-10-18 | |
http://www.wireshark.org/security/wnpa-sec-2006-01.html | 2018-10-18 |
URL | Date | SRC |
---|---|---|
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P | 2018-10-18 | |
http://rhn.redhat.com/errata/RHSA-2006-0602.html | 2018-10-18 | |
http://secunia.com/advisories/21121 | 2018-10-18 | |
http://secunia.com/advisories/21204 | 2018-10-18 | |
http://secunia.com/advisories/21249 | 2018-10-18 | |
http://secunia.com/advisories/21467 | 2018-10-18 | |
http://secunia.com/advisories/21488 | 2018-10-18 | |
http://secunia.com/advisories/21598 | 2018-10-18 | |
http://secunia.com/advisories/22089 | 2018-10-18 | |
http://security.gentoo.org/glsa/glsa-200607-09.xml | 2018-10-18 | |
http://www.debian.org/security/2006/dsa-1127 | 2018-10-18 | |
http://www.mandriva.com/security/advisories?name=MDKSA-2006:128 | 2018-10-18 | |
http://www.novell.com/linux/security/advisories/2006_20_sr.html | 2018-10-18 | |
http://www.vupen.com/english/advisories/2006/2850 | 2018-10-18 | |
https://access.redhat.com/security/cve/CVE-2006-3628 | 2006-08-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1618147 | 2006-08-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.0 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.0" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.0a Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.0a" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.1 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.1" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.2 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.2" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.3 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.3" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.4 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.4" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.5 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.5" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.6 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.6" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.7 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.7" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.8 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.8" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.9 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.9" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.10 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.10" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.11 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.11" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.12 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.12" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.13 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.13" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.10.14 Search vendor "Ethereal Group" for product "Ethereal" and version "0.10.14" | - |
Affected
| ||||||
Ethereal Group Search vendor "Ethereal Group" | Ethereal Search vendor "Ethereal Group" for product "Ethereal" | 0.99.0 Search vendor "Ethereal Group" for product "Ethereal" and version "0.99.0" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 0.10 Search vendor "Wireshark" for product "Wireshark" and version "0.10" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 0.10.4 Search vendor "Wireshark" for product "Wireshark" and version "0.10.4" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 0.10.13 Search vendor "Wireshark" for product "Wireshark" and version "0.10.13" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 0.99 Search vendor "Wireshark" for product "Wireshark" and version "0.99" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 0.99.1 Search vendor "Wireshark" for product "Wireshark" and version "0.99.1" | - |
Affected
|