{"api_version":"1","generated_at":"2026-07-23T11:40:19+00:00","cve":"CVE-2005-0739","urls":{"html":"https://cve.report/CVE-2005-0739","api":"https://cve.report/api/cve/CVE-2005-0739.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0739","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0739"},"summary":{"title":"CVE-2005-0739","description":"The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.","state":"PUBLISHED","assigner":"debian","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707","name":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"Ethereal - This Ultra Rare Brand Concept is Available for Purchase.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Ethereal: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12762","name":"http://www.securityfocus.com/bid/12762","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ethereal Etheric/GPRS-LLC/IAPP/JXTA/sFlow Dissector Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-306.html","name":"http://www.redhat.com/support/errata/RHSA-2005-306.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:053","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:053","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories - Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html","name":"http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[FLSA-2006:152922] Updated ethereal packages fix security issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=111066805726551&w=2","name":"http://marc.info/?l=bugtraq&m=111066805726551&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Ethereal remote buffer overflow #2' - MARC","mime":"text/x-c","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2005/dsa-718","name":"http://www.debian.org/security/2005/dsa-718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Debian -- Security Information -- DSA-718-2 ethereal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05","name":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.ethereal.com/appnotes/enpa-sa-00018.html","name":"http://www.ethereal.com/appnotes/enpa-sa-00018.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","URL Repurposed"],"title":"Ethereal: enpa-sa-00018","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0739","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0739","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"739","vulnerable":"1","versionEndIncluding":"0.10.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ethereal_group","cpe5":"ethereal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:21:06.594Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"GLSA-200503-16","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml"},{"name":"MDKSA-2005:053","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:053"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ethereal.com/appnotes/enpa-sa-00018.html"},{"name":"RHSA-2005:306","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-306.html"},{"name":"oval:org.mitre.oval:def:9687","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687"},{"name":"FLSA-2006:152922","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html"},{"name":"DSA-718","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2005/dsa-718"},{"name":"20050312 Ethereal remote buffer overflow #2","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111066805726551&w=2"},{"name":"12762","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12762"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-03-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"79363d38-fa19-49d1-9214-5f28da3f3ac5","shortName":"debian"},"references":[{"name":"GLSA-200503-16","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml"},{"name":"MDKSA-2005:053","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:053"},{"tags":["x_refsource_MISC"],"url":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707"},{"tags":["x_refsource_MISC"],"url":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ethereal.com/appnotes/enpa-sa-00018.html"},{"name":"RHSA-2005:306","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-306.html"},{"name":"oval:org.mitre.oval:def:9687","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687"},{"name":"FLSA-2006:152922","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html"},{"name":"DSA-718","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2005/dsa-718"},{"name":"20050312 Ethereal remote buffer overflow #2","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111066805726551&w=2"},{"name":"12762","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12762"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@debian.org","ID":"CVE-2005-0739","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-200503-16","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml"},{"name":"MDKSA-2005:053","refsource":"MANDRAKE","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:053"},{"name":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707","refsource":"MISC","url":"http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707"},{"name":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05","refsource":"MISC","url":"http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05"},{"name":"http://www.ethereal.com/appnotes/enpa-sa-00018.html","refsource":"CONFIRM","url":"http://www.ethereal.com/appnotes/enpa-sa-00018.html"},{"name":"RHSA-2005:306","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2005-306.html"},{"name":"oval:org.mitre.oval:def:9687","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687"},{"name":"FLSA-2006:152922","refsource":"FEDORA","url":"http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html"},{"name":"DSA-718","refsource":"DEBIAN","url":"http://www.debian.org/security/2005/dsa-718"},{"name":"20050312 Ethereal remote buffer overflow #2","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111066805726551&w=2"},{"name":"12762","refsource":"BID","url":"http://www.securityfocus.com/bid/12762"}]}}}},"cveMetadata":{"assignerOrgId":"79363d38-fa19-49d1-9214-5f28da3f3ac5","assignerShortName":"debian","cveId":"CVE-2005-0739","datePublished":"2005-03-13T05:00:00.000Z","dateReserved":"2005-03-13T00:00:00.000Z","dateUpdated":"2024-08-07T21:21:06.594Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ethereal_group:ethereal:*:*:*:*:*:*:*:*","versionEndIncluding":"0.10.9","matchCriteriaId":"08D3F4F1-432B-4AA7-9312-768C0123DB4A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"739","Ordinal":"1","Title":"CVE-2005-0739","CVE":"CVE-2005-0739","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"739","Ordinal":"1","NoteData":"The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.","Type":"Description","Title":"CVE-2005-0739"},{"CveYear":"2005","CveId":"739","Ordinal":"2","NoteData":"2005-03-13","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"739","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}