PT-2006-2917 · Ethereal · Ethereal

Gerald Combs

·

Published

2006-04-25

·

Updated

2024-02-14

·

CVE-2006-1933

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ethereal versions 0.10.x up to 0.10.14
Description The issue involves multiple unspecified vulnerabilities that allow remote attackers to cause a denial of service through crafted packets to the (1) UMA and (2) BER dissectors, potentially leading to large or infinite loops.
Recommendations For Ethereal versions 0.10.x up to 0.10.14, consider disabling the UMA and BER dissectors as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2006-1933
DSA-1049-1
RHSA-2006:0420

Affected Products

Ethereal