PT-2006-2921 · Ethereal · Ethereal

Gerald Combs

·

Published

2006-04-25

·

Updated

2024-02-14

·

CVE-2006-1937

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ethereal versions 0.10.x up to 0.10.14
Description The issue affects multiple components, including H.248, X.509if, SRVLOC, H.245, AIM, and general packet dissectors, as well as the statistics counter. Remote attackers can cause a denial of service, leading to a crash due to a null dereference.
Recommendations For Ethereal versions 0.10.x up to 0.10.14, consider disabling the affected dissectors, such as H.248, X.509if, SRVLOC, H.245, AIM, and general packet dissectors, until a fix is available. Additionally, restrict access to the statistics counter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2006-1937
DSA-1049-1
RHSA-2006:0420

Affected Products

Ethereal