CVE-2005-0739
Summary
| CVE | CVE-2005-0739 |
|---|---|
| State | PUBLISHED |
| Assigner | debian |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-02 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ethereal Group | Ethereal | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ethereal - This Ultra Rare Brand Concept is Available for Purchase. | af854a3a-2127-422b-91ae-364da2661108 | anonsvn.ethereal.com | URL Repurposed |
| Gentoo Linux Documentation -- Ethereal: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Ethereal Etheric/GPRS-LLC/IAPP/JXTA/sFlow Dissector Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [FLSA-2006:152922] Updated ethereal packages fix security issues | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 'Ethereal remote buffer overflow #2' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Debian -- Security Information -- DSA-718-2 ethereal | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | security.lss.hr | |
| Ethereal: enpa-sa-00018 | af854a3a-2127-422b-91ae-364da2661108 | www.ethereal.com | Patch, URL Repurposed |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.