CVE-2003-0356
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.
Published
2003-06-09T04:00:00.000
Last Modified
2025-04-03T01:03:51.193
Status
Deferred
Source
[email protected]
Severity
CVSSv3.1: 9.8 (CRITICAL)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: COMPLETE
- Integrity Impact: COMPLETE
- Availability Impact: COMPLETE
Exploitability Score
10.0
Impact Score
10.0
Weaknesses
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
ethereal
|
ethereal
|
< 0.9.12 |
Yes
|
References
-
http://www.debian.org/security/2003/dsa-313
Broken Link, Patch, Vendor Advisory
([email protected])
-
http://www.ethereal.com/appnotes/enpa-sa-00009.html
Broken Link, Patch, Vendor Advisory
([email protected])
-
http://www.kb.cert.org/vuls/id/641013
Third Party Advisory, US Government Resource
([email protected])
-
http://www.mandriva.com/security/advisories?name=MDKSA-2003:067
Third Party Advisory
([email protected])
-
http://www.redhat.com/support/errata/RHSA-2003-077.html
Broken Link
([email protected])
-
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69
Broken Link
([email protected])
-
http://www.debian.org/security/2003/dsa-313
Broken Link, Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.ethereal.com/appnotes/enpa-sa-00009.html
Broken Link, Patch, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.kb.cert.org/vuls/id/641013
Third Party Advisory, US Government Resource
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.mandriva.com/security/advisories?name=MDKSA-2003:067
Third Party Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.redhat.com/support/errata/RHSA-2003-077.html
Broken Link
(af854a3a-2127-422b-91ae-364da2661108)
-
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69
Broken Link
(af854a3a-2127-422b-91ae-364da2661108)