PT-2003-1623 · Ethereal · Ethereal
Published
2003-06-18
·
Updated
2024-02-14
·
CVE-2003-0432
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Ethereal versions 0.9.12 and earlier
Description:
The issue is related to the improper handling of certain strings in multiple dissectors, including
BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI. The consequences of this issue are unknown.Recommendations:
For Ethereal versions 0.9.12 and earlier, consider disabling or restricting the use of the affected dissectors until a patch is available. As a temporary workaround, avoid using the dissectors for
BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ethereal