PT-2005-3279 · Ethereal+1 · Ethereal+1

CVE-2005-2364

·

Published

2005-08-10

·

Updated

2024-02-14

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ethereal versions 0.8.20 through 0.10.11
Description The issue is related to unknown vulnerabilities in certain dissectors, which can cause a denial of service. This happens when the application encounters specific packets that lead to a null pointer dereference, resulting in an application crash.
Recommendations For Ethereal versions 0.8.20 through 0.10.11, consider updating to a version where these issues are fixed, if available. As a temporary workaround, restrict the use of the GIOP, WBXML, and CAMEL dissectors to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2364
DSA-853-1
RHSA-2005:687
RHSA-2005_687

Affected Products

Ethereal
Red Hat