security flaw
Published Oct 28, 2006
7.5
HIGHCVSS 3.1
EPSS 4.42%
Description
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Affected products
No data.
No data.
Red Hat Enterprise Linux 2.1
wireshark-0:0.99.4-AS21.1
Fixed · RHSA-2006:0726
Red Hat Enterprise Linux 3
wireshark-0:0.99.4-EL3.1
Fixed · RHSA-2006:0726
Red Hat Enterprise Linux 4
wireshark-0:0.99.4-EL4.1
Fixed · RHSA-2006:0726
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | wireshark-0:0.99.4-AS21.1 | Fixed | RHSA-2006:0726 |
| Red Hat Enterprise Linux 3 | wireshark-0:0.99.4-EL3.1 | Fixed | RHSA-2006:0726 |
| Red Hat Enterprise Linux 4 | wireshark-0:0.99.4-EL4.1 | Fixed | RHSA-2006:0726 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 17, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.42% (0.04419) | 91.04th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.06% (0.04062) | 89.31th | v5 (v2026.06.15) |
| Jun 16, 2025 | 6.82% (0.06819) | 90.84th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.71% (0.05714) | 89.49th | v4 (v2025.03.14) |
| Mar 29, 2025 | 12.72% (0.12717) | 89.97th | v4 (v2025.03.14) |
| Mar 17, 2025 | 6.34% (0.06338) | 90.28th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.81% (0.00811) | 82.46th | v3 (v2023.03.01) |
| May 9, 2024 | 0.78% (0.00784) | 81.34th | v3 (v2023.03.01) |
| Feb 16, 2024 | 0.97% (0.00968) | 82.86th | v3 (v2023.03.01) |
| Oct 8, 2023 | 1.87% (0.01873) | 87.04th | v3 (v2023.03.01) |
| Aug 31, 2023 | 1.14% (0.01144) | 82.97th | v3 (v2023.03.01) |
| Jul 24, 2023 | 0.81% (0.00809) | 79.50th | v3 (v2023.03.01) |
| Jun 16, 2023 | 0.50% (0.00502) | 73.08th | v3 (v2023.03.01) |
| Mar 31, 2023 | 0.48% (0.00484) | 72.32th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.40% (0.00395) | 69.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (26)
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P vendor-advisoryx_refsource_SGIBroken Link
- http://secunia.com/advisories/22590 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://secunia.com/advisories/22659 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22672 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22692 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22797 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22841 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/22929 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/23096 third-party-advisoryx_refsource_SECUNIABroken Link
- http://securitytracker.com/id?1017129 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-255.htm x_refsource_CONFIRMThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:195 vendor-advisoryx_refsource_MANDRIVAThird Party Advisory
- http://www.novell.com/linux/security/advisories/2006_65_ethereal.html vendor-advisoryx_refsource_SUSEBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0726.html vendor-advisoryx_refsource_REDHATBroken Link
- http://www.securityfocus.com/archive/1/450307/100/0/threaded mailing-listx_refsource_BUGTRAQBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/20762 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.us.debian.org/security/2006/dsa-1201 vendor-advisoryx_refsource_DEBIANBroken Link
- http://www.vupen.com/english/advisories/2006/4220 vdb-entryx_refsource_VUPENBroken Link
- http://www.wireshark.org/security/wnpa-sec-2006-03.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2006-4574 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1618197 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29844 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://issues.rpath.com/browse/RPL-746 x_refsource_CONFIRMBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2006-4574
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9740 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2006-4574
Change history (0)
No recorded changes yet.