VulnerabilityModified
CVE-2005-2364
Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to cause a denial of service (application crash) via certain packets that cause a null pointer dereference.
MEDIUM 5.0EPSS 3.59%
Does this matter?
Lower severity and a low EPSS score (3.59%). Track it; it rarely justifies an emergency change on its own.
Description
Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to cause a denial of service (application crash) via certain packets that cause a null pointer dereference.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.59% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- ethereal group/ethereal
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/16225/
- http://secunia.com/advisories/17102
- http://www.debian.org/security/2005/dsa-853
- http://www.ethereal.com/appnotes/enpa-sa-00020.htmlPatch, URL Repurposed
- http://www.gentoo.org/security/en/glsa/glsa-200507-27.xmlPatch
- http://www.novell.com/linux/security/advisories/2005_19_sr.html
- http://www.osvdb.org/18386
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-687.html
- http://www.securityfocus.com/bid/14399
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10007
- http://secunia.com/advisories/16225/
- http://secunia.com/advisories/17102
- http://www.debian.org/security/2005/dsa-853
- http://www.ethereal.com/appnotes/enpa-sa-00020.htmlPatch, URL Repurposed
- http://www.gentoo.org/security/en/glsa/glsa-200507-27.xmlPatch
- http://www.novell.com/linux/security/advisories/2005_19_sr.html
- http://www.osvdb.org/18386
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-687.html
- http://www.securityfocus.com/bid/14399
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10007
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.