| Vulnerability Name: | CVE-2003-0432 (CCN-12320) | ||||||||||||||||
| Assigned: | 2003-06-11 | ||||||||||||||||
| Published: | 2003-06-11 | ||||||||||||||||
| Updated: | 2017-10-11 | ||||||||||||||||
| Summary: | Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors. | ||||||||||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: CCN Type: SCO Security Advisory CSSA-2003-030.0 OpenLinux: Multiple vulnerabilities have reported in Ethereal 0.9.12 Source: SCO Type: UNKNOWN CSSA-2003-030.0 Source: MITRE Type: CNA CVE-2003-0432 Source: CONECTIVA Type: UNKNOWN CLA-2003:662 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:662 ethereal Source: CCN Type: RHSA-2003-077 ethereal security update Source: CCN Type: RHSA-2003-203 Updated Ethereal packages fix security issues Source: CCN Type: SA9007 Ethereal Multiple Protocol Dissector Vulnerabilities Source: SECUNIA Type: UNKNOWN 9007 Source: DEBIAN Type: Patch, Vendor Advisory DSA-324 Source: DEBIAN Type: DSA-324 ethereal -- several vulnerabilities Source: CCN Type: Ethereal Security Advisories enpa-sa-00010 Several security problems in Ethereal 0.9.12 Source: CCN Type: Ethereal Security Advisory enpa-sa-00010 Several security problems in Ethereal 0.9.12 Source: CONFIRM Type: Patch, Vendor Advisory http://www.ethereal.com/appnotes/enpa-sa-00010.html Source: CCN Type: Gentoo Linux Security Announcement 200306-13 ethereal Source: REDHAT Type: UNKNOWN RHSA-2003:077 Source: CCN Type: BID-7881 Ethereal Multiple Dissector String Handling Vulnerabilities Source: XF Type: UNKNOWN ethereal-dissectors-code-execution(12320) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:106 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||