PT-2003-1623 · Ethereal · Ethereal

Published

2003-06-18

·

Updated

2024-02-14

·

CVE-2003-0432

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Ethereal versions 0.9.12 and earlier
Description: The issue is related to the improper handling of certain strings in multiple dissectors, including BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI. The consequences of this issue are unknown.
Recommendations: For Ethereal versions 0.9.12 and earlier, consider disabling or restricting the use of the affected dissectors until a patch is available. As a temporary workaround, avoid using the dissectors for BGP, WTP, DNS, 802.11, ISAKMP, WSP, CLNP, ISIS, and RMI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2003-0432
DSA-324

Affected Products

Ethereal