Ethereal TVB_GET_NSTRINGZ0() Memory Handling Vulnerability
BID:7883
Info
Ethereal TVB_GET_NSTRINGZ0() Memory Handling Vulnerability
| Bugtraq ID: | 7883 |
| Class: | Design Error |
| CVE: |
CVE-2003-0431 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability credited to Timo Sirainen. |
| Vulnerable: |
SCO OpenLinux Workstation 3.1.1 SCO OpenLinux Server 3.1.1 Redhat Linux Advanced Work Station 2.1 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 2.1 Ethereal Group Ethereal 0.9.12 Ethereal Group Ethereal 0.9.11 Ethereal Group Ethereal 0.9.10 Ethereal Group Ethereal 0.9.9 Ethereal Group Ethereal 0.9.8 Ethereal Group Ethereal 0.9.7 Ethereal Group Ethereal 0.9.6 Ethereal Group Ethereal 0.9.5 Ethereal Group Ethereal 0.9.4 Ethereal Group Ethereal 0.9.3 Ethereal Group Ethereal 0.9.2 Ethereal Group Ethereal 0.9.1 Ethereal Group Ethereal 0.9 |
| Not Vulnerable: |
Ethereal Group Ethereal 0.9.13 |
Discussion
Ethereal TVB_GET_NSTRINGZ0() Memory Handling Vulnerability
An Ethereal routine, tvb_get_nstringz0(), has been reported prone to a memory handling vulnerability. Reportedly tvb_get_nstringz0() incorrectly handles a zero-length buffer size.
Exploitation of this issue may allow an attacker to cause Ethereal to behave in an unpredictable manner.
The precise technical details of this vulnerability are currently unknown. This BID will be updated, as further information is available.
An Ethereal routine, tvb_get_nstringz0(), has been reported prone to a memory handling vulnerability. Reportedly tvb_get_nstringz0() incorrectly handles a zero-length buffer size.
Exploitation of this issue may allow an attacker to cause Ethereal to behave in an unpredictable manner.
The precise technical details of this vulnerability are currently unknown. This BID will be updated, as further information is available.
Exploit / POC
Ethereal TVB_GET_NSTRINGZ0() Memory Handling Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.