CVE-2004-0176
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 67.09% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- ethereal group/ethereal
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
- http://marc.info/?l=bugtraq&m=108007072215742&w=2
- http://marc.info/?l=bugtraq&m=108058005324316&w=2
- http://marc.info/?l=bugtraq&m=108213710306260&w=2
- http://secunia.com/advisories/11185
- http://security.e-matters.de/advisories/032004.html
- http://security.gentoo.org/glsa/glsa-200403-07.xml
- http://www.debian.org/security/2004/dsa-511Patch, Vendor Advisory
- http://www.ethereal.com/appnotes/enpa-sa-00013.htmlURL Repurposed
- http://www.kb.cert.org/vuls/id/119876US Government Resource
- http://www.kb.cert.org/vuls/id/125156US Government Resource
- http://www.kb.cert.org/vuls/id/433596US Government Resource
- http://www.kb.cert.org/vuls/id/591820US Government Resource
- http://www.kb.cert.org/vuls/id/644886US Government Resource
- http://www.kb.cert.org/vuls/id/659140US Government Resource
- http://www.kb.cert.org/vuls/id/740188US Government Resource
- http://www.kb.cert.org/vuls/id/864884US Government Resource
- http://www.kb.cert.org/vuls/id/931588US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
- http://www.osvdb.org/6893
- http://www.redhat.com/support/errata/RHSA-2004-136.html
- http://www.redhat.com/support/errata/RHSA-2004-137.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15569
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10187
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A878
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A887
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
- http://marc.info/?l=bugtraq&m=108007072215742&w=2
- http://marc.info/?l=bugtraq&m=108058005324316&w=2
- http://marc.info/?l=bugtraq&m=108213710306260&w=2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.