Vulnerabilities > CVE-2004-0505

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_74D06B67D2CF11D8B47902E0185C0B53.NASL
    descriptionIssues have been discovered in multiple protocol dissectors.
    last seen2020-06-01
    modified2020-06-02
    plugin id37398
    published2009-04-23
    reporterThis script is Copyright (C) 2009-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/37398
    titleFreeBSD : multiple vulnerabilities in ethereal (74d06b67-d2cf-11d8-b479-02e0185c0b53)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200406-01.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200406-01 (Ethereal: Multiple security problems) There are multiple vulnerabilities in versions of Ethereal earlier than 0.10.4, including: A buffer overflow in the MMSE dissector. Under specific conditions a SIP packet could make Ethereal crash. The AIM dissector could throw an assertion, causing Ethereal to crash. The SPNEGO dissector could dereference a NULL pointer, causing a crash. Impact : An attacker could use these vulnerabilities to crash Ethereal or even execute arbitrary code with the permissions of the user running Ethereal, which could be the root user. Workaround : For a temporary workaround you can disable all affected protocol dissectors by selecting Analyze->Enabled Protocols... and deselecting them from the list. However, it is strongly recommended to upgrade to the latest stable release.
    last seen2020-06-01
    modified2020-06-02
    plugin id14512
    published2004-08-30
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14512
    titleGLSA-200406-01 : Ethereal: Multiple security problems
  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2004-234.NASL
    descriptionUpdated Ethereal packages that fix various security vulnerabilities are now available. Ethereal is a program for monitoring network traffic. The MMSE dissector in Ethereal releases 0.10.1 through 0.10.3 contained a buffer overflow flaw. On a system where Ethereal is running, a remote attacker could send malicious packets that could cause Ethereal to crash or execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0507 to this issue. In addition, other flaws in Ethereal prior to 0.10.4 were found that could cause it to crash in response to carefully crafted SIP (CVE-2004-0504), AIM (CVE-2004-0505), or SPNEGO (CVE-2004-0506) packets. Users of Ethereal should upgrade to these updated packages, which contain backported security patches that correct these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id12501
    published2004-07-06
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/12501
    titleRHEL 2.1 / 3 : ethereal (RHSA-2004:234)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_ETHEREAL_0104.NASL
    descriptionThe following package needs to be updated: ethereal
    last seen2016-09-26
    modified2011-10-03
    plugin id12645
    published2004-07-11
    reporterTenable
    sourcehttps://www.tenable.com/plugins/index.php?view=single&id=12645
    titleFreeBSD : multiple vulnerabilities in ethereal (41)

Oval

  • accepted2013-04-29T04:19:23.074-04:00
    classvulnerability
    contributors
    • nameAharon Chernin
      organizationSCAP.com, LLC
    • nameDragos Prisaca
      organizationG2, Inc.
    definition_extensions
    • commentThe operating system installed on the system is Red Hat Enterprise Linux 3
      ovaloval:org.mitre.oval:def:11782
    • commentCentOS Linux 3.x
      ovaloval:org.mitre.oval:def:16651
    descriptionThe AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
    familyunix
    idoval:org.mitre.oval:def:9433
    statusaccepted
    submitted2010-07-09T03:56:16-04:00
    titleThe AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
    version26
  • accepted2004-07-12T12:00:00.000-04:00
    classvulnerability
    contributors
    nameJay Beale
    organizationBastille Linux
    descriptionThe AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
    familyunix
    idoval:org.mitre.oval:def:986
    statusaccepted
    submitted2004-06-10T12:00:00.000-04:00
    titleEthereal AIM Dissector Vulnerability
    version4

Redhat

advisories
rhsa
idRHSA-2004:234
rpms
  • ethereal-0:0.10.3-0.30E.2
  • ethereal-debuginfo-0:0.10.3-0.30E.2
  • ethereal-gnome-0:0.10.3-0.30E.2