Vulnerability Name: | CVE-2004-0176 (CCN-15569) | ||||||||||||||||||||||||||||
Assigned: | 2004-03-04 | ||||||||||||||||||||||||||||
Published: | 2004-03-04 | ||||||||||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||||||||||
Summary: | Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0176 Source: CONECTIVA Type: UNKNOWN CLA-2004:835 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:835 ethereal Source: BUGTRAQ Type: UNKNOWN 20040323 Advisory 03/2004: Multiple (13) Ethereal remote overflows Source: BUGTRAQ Type: UNKNOWN 20040329 LNSA-#2004-0007: Multiple security problems in Ethereal Source: BUGTRAQ Type: UNKNOWN 20040416 [OpenPKG-SA-2004.015] OpenPKG Security Advisory (ethereal) Source: CCN Type: e-matters Security Advisory 03/2004 Multiple (13) Ethereal remote overflows Source: CCN Type: RHSA-2004-136 ethereal security update Source: CCN Type: RHSA-2004-137 Updated Ethereal packages fix security issues Source: CCN Type: SA11185 Ethereal Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 11185 Source: MISC Type: UNKNOWN http://security.e-matters.de/advisories/032004.html Source: GENTOO Type: UNKNOWN GLSA-200403-07 Source: CCN Type: CIAC Information Bulletin 0-105 Multiple Vulnerabilities in Ethereal 0.10.2 Source: DEBIAN Type: Patch, Vendor Advisory DSA-511 Source: DEBIAN Type: DSA-511 ethereal -- buffer overflows Source: CCN Type: Ethereal Web site The Ethereal Network Analyzer Source: CCN Type: Ethereal Application Note enpa-sa-00013 Multiple security problems in Ethereal 0.10.2 Source: CONFIRM Type: UNKNOWN http://www.ethereal.com/appnotes/enpa-sa-00013.html Source: CCN Type: GLSA-200403-07 Multiple remote overflows and vulnerabilities in Ethereal Source: CCN Type: US-CERT VU#119876 Ethereal contains multiple vulnerabilities in the EIGRP protocol dissector Source: CERT-VN Type: US Government Resource VU#119876 Source: CCN Type: US-CERT VU#125156 Ethereal contains multiple vulnerabilities in the UCP protocol dissector Source: CERT-VN Type: US Government Resource VU#125156 Source: CCN Type: US-CERT VU#433596 Ethereal integer underflow when parsing malformed PGM packets with NAK lists Source: CERT-VN Type: US Government Resource VU#433596 Source: CCN Type: US-CERT VU#591820 Ethereal fails to properly decode Transaction IDs within TCAP packets Source: CERT-VN Type: US Government Resource VU#591820 Source: CCN Type: US-CERT VU#644886 Ethereal fails to properly parse NetFlow UDP packets with an overly large template_entry count Source: CERT-VN Type: US Government Resource VU#644886 Source: CCN Type: US-CERT VU#659140 Ethereal ISUP protocol dissector fails to properly decode ISUP packets Source: CERT-VN Type: US Government Resource VU#659140 Source: CCN Type: US-CERT VU#740188 Ethereal IrDA dissector plugin fails to properly parse IRCOM_PORT_NAME parameter Source: CERT-VN Type: US Government Resource VU#740188 Source: CCN Type: US-CERT VU#864884 Ethereal contains multiple vulnerabilities in the IGAP protocol dissector Source: CERT-VN Type: US Government Resource VU#864884 Source: CCN Type: US-CERT VU#931588 Ethereal fails to properly decode BGP packets containing MPLS IPv6 labels Source: CERT-VN Type: US Government Resource VU#931588 Source: CCN Type: GLSA 200403-07 Multiple remote overflows and vulnerabilities in Ethereal Source: MANDRAKE Type: UNKNOWN MDKSA-2004:024 Source: CCN Type: OpenPKG-SA-2004.015 ethereal Source: OSVDB Type: UNKNOWN 6893 Source: CCN Type: OSVDB ID: 6893 Ethereal BGP Dissector MPLS Label Overflow Source: REDHAT Type: UNKNOWN RHSA-2004:136 Source: REDHAT Type: UNKNOWN RHSA-2004:137 Source: CCN Type: SecuriTeam Mailing List, Security Holes & Exploits 30 Mar 2004 Ethereal EIGRP Dissector Buffer Overflow Exploit Source: CCN Type: BID-9952 Ethereal Multiple Vulnerabilities Source: CCN Type: USN-82-1 Linux kernel vulnerabilities Source: XF Type: UNKNOWN ethereal-multiple-dissectors-bo(15569) Source: XF Type: UNKNOWN ethereal-multiple-dissectors-bo(15569) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10187 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:878 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:887 Source: SUSE Type: SUSE-SA:2004:012 mc: local privilege escalation | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |