CVE-2006-4574
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.20% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-193, CWE-617
- Affected
- wireshark/wireshark
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-PBroken Link
- http://secunia.com/advisories/22590Broken Link, Vendor Advisory
- http://secunia.com/advisories/22659Broken Link
- http://secunia.com/advisories/22672Broken Link
- http://secunia.com/advisories/22692Broken Link
- http://secunia.com/advisories/22797Broken Link
- http://secunia.com/advisories/22841Broken Link
- http://secunia.com/advisories/22929Broken Link
- http://secunia.com/advisories/23096Broken Link
- http://securitytracker.com/id?1017129Broken Link, Third Party Advisory, VDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-255.htmThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:195Third Party Advisory
- http://www.novell.com/linux/security/advisories/2006_65_ethereal.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0726.htmlBroken Link
- http://www.securityfocus.com/archive/1/450307/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/20762Broken Link, Third Party Advisory, VDB Entry
- http://www.us.debian.org/security/2006/dsa-1201Broken Link
- http://www.vupen.com/english/advisories/2006/4220Broken Link
- http://www.wireshark.org/security/wnpa-sec-2006-03.htmlThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29844Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-746Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9740Broken Link
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-PBroken Link
- http://secunia.com/advisories/22590Broken Link, Vendor Advisory
- http://secunia.com/advisories/22659Broken Link
- http://secunia.com/advisories/22672Broken Link
- http://secunia.com/advisories/22692Broken Link
- http://secunia.com/advisories/22797Broken Link
- http://secunia.com/advisories/22841Broken Link
- http://secunia.com/advisories/22929Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.