Vulnerabilities > CVE-2004-0504

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_74D06B67D2CF11D8B47902E0185C0B53.NASL
    descriptionIssues have been discovered in multiple protocol dissectors.
    last seen2020-06-01
    modified2020-06-02
    plugin id37398
    published2009-04-23
    reporterThis script is Copyright (C) 2009-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/37398
    titleFreeBSD : multiple vulnerabilities in ethereal (74d06b67-d2cf-11d8-b479-02e0185c0b53)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200406-01.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200406-01 (Ethereal: Multiple security problems) There are multiple vulnerabilities in versions of Ethereal earlier than 0.10.4, including: A buffer overflow in the MMSE dissector. Under specific conditions a SIP packet could make Ethereal crash. The AIM dissector could throw an assertion, causing Ethereal to crash. The SPNEGO dissector could dereference a NULL pointer, causing a crash. Impact : An attacker could use these vulnerabilities to crash Ethereal or even execute arbitrary code with the permissions of the user running Ethereal, which could be the root user. Workaround : For a temporary workaround you can disable all affected protocol dissectors by selecting Analyze->Enabled Protocols... and deselecting them from the list. However, it is strongly recommended to upgrade to the latest stable release.
    last seen2020-06-01
    modified2020-06-02
    plugin id14512
    published2004-08-30
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14512
    titleGLSA-200406-01 : Ethereal: Multiple security problems
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2004-234.NASL
    descriptionUpdated Ethereal packages that fix various security vulnerabilities are now available. Ethereal is a program for monitoring network traffic. The MMSE dissector in Ethereal releases 0.10.1 through 0.10.3 contained a buffer overflow flaw. On a system where Ethereal is running, a remote attacker could send malicious packets that could cause Ethereal to crash or execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0507 to this issue. In addition, other flaws in Ethereal prior to 0.10.4 were found that could cause it to crash in response to carefully crafted SIP (CVE-2004-0504), AIM (CVE-2004-0505), or SPNEGO (CVE-2004-0506) packets. Users of Ethereal should upgrade to these updated packages, which contain backported security patches that correct these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id12501
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12501
    titleRHEL 2.1 / 3 : ethereal (RHSA-2004:234)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_ETHEREAL_0104.NASL
    descriptionThe following package needs to be updated: ethereal
    last seen2016-09-26
    modified2011-10-03
    plugin id12645
    published2004-07-11
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=12645
    titleFreeBSD : multiple vulnerabilities in ethereal (41)

Oval

  • accepted2013-04-29T04:22:01.222-04:00
    classvulnerability
    contributors
    • nameAharon Chernin
      organizationSCAP.com, LLC
    • nameDragos Prisaca
      organizationG2, Inc.
    definition_extensions
    • commentThe operating system installed on the system is Red Hat Enterprise Linux 3
      ovaloval:org.mitre.oval:def:11782
    • commentCentOS Linux 3.x
      ovaloval:org.mitre.oval:def:16651
    descriptionEthereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
    familyunix
    idoval:org.mitre.oval:def:9769
    statusaccepted
    submitted2010-07-09T03:56:16-04:00
    titleEthereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
    version26
  • accepted2004-07-12T12:00:00.000-04:00
    classvulnerability
    contributors
    nameJay Beale
    organizationBastille Linux
    descriptionEthereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
    familyunix
    idoval:org.mitre.oval:def:982
    statusaccepted
    submitted2004-06-10T12:00:00.000-04:00
    titleEthereal Denial of Service via SIP Messages
    version4

Redhat

advisories
rhsa
idRHSA-2004:234
rpms
  • ethereal-0:0.10.3-0.30E.2
  • ethereal-debuginfo-0:0.10.3-0.30E.2
  • ethereal-gnome-0:0.10.3-0.30E.2