PT-2005-3279 · Ethereal+1 · Ethereal+1
Published
2005-08-10
·
Updated
2024-02-14
·
CVE-2005-2364
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Ethereal versions 0.8.20 through 0.10.11
Description
The issue is related to unknown vulnerabilities in certain dissectors, which can cause a denial of service. This happens when the application encounters specific packets that lead to a null pointer dereference, resulting in an application crash.
Recommendations
For Ethereal versions 0.8.20 through 0.10.11, consider updating to a version where these issues are fixed, if available. As a temporary workaround, restrict the use of the GIOP, WBXML, and CAMEL dissectors to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ethereal
Red Hat