PT-2005-4059 · Ethereal+1 · Ethereal+1
Published
2005-10-25
·
Updated
2024-02-14
·
CVE-2005-3245
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Ethereal versions 0.10.3 through 0.10.12
Description
The issue is related to an unspecified vulnerability in the ONC RPC dissector. When the "Dissect unknown RPC program numbers" option is enabled, it allows remote attackers to cause a denial of service due to memory consumption.
Recommendations
For Ethereal versions 0.10.3 through 0.10.12, consider disabling the "Dissect unknown RPC program numbers" option as a temporary workaround to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ethereal
Red Hat