MEDIUM
security flaw
Published Mar 13, 2005
5.0
MEDIUMCVSS 2.0
EPSS 7.61%
Description
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
Affected products
No data.
- ≤ 0.10.9
No data.
Red Hat Enterprise Linux 3
ethereal-0:0.10.10-1.EL3.1
Fixed · RHSA-2005:306
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | ethereal-0:0.10.10-1.EL3.1 | Fixed | RHSA-2005:306 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707 x_refsource_MISCURL Repurposed
- http://marc.info/?l=bugtraq&m=111066805726551&w=2 mailing-listx_refsource_BUGTRAQ
- http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05 x_refsource_MISC
- http://www.debian.org/security/2005/dsa-718 vendor-advisoryx_refsource_DEBIANPatch
- http://www.ethereal.com/appnotes/enpa-sa-00018.html x_refsource_CONFIRMPatchURL Repurposed
- http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:053 vendor-advisoryx_refsource_MANDRAKE
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html vendor-advisoryx_refsource_FEDORA
- http://www.redhat.com/support/errata/RHSA-2005-306.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/12762 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2005-0739 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617565 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2005-0739
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-0739
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Mar 13, 2005
Updated Aug 7, 2024
Reserved Mar 13, 2005
Link CVE-2005-0739
CISA Vulnrichment
Updated n/a