CVE-2005-0739
Severity CVSS v4.0:
Pending analysis
Type:
CWE-189
Numeric Errors
Publication date:
02/05/2005
Last modified:
03/04/2025
Description
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:ethereal_group:ethereal:*:*:*:*:*:*:*:* | 0.10.9 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707
- http://marc.info/?l=bugtraq&m=111066805726551&w=2
- http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05
- http://www.debian.org/security/2005/dsa-718
- http://www.ethereal.com/appnotes/enpa-sa-00018.html
- http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A053
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-306.html
- http://www.securityfocus.com/bid/12762
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687
- http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707
- http://marc.info/?l=bugtraq&m=111066805726551&w=2
- http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05
- http://www.debian.org/security/2005/dsa-718
- http://www.ethereal.com/appnotes/enpa-sa-00018.html
- http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2005%3A053
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-306.html
- http://www.securityfocus.com/bid/12762
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687