CVE-2003-0356
N/A
N/A
Summary
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.kb.cert.org/vuls/id/641013
- http://www.redhat.com/support/errata/RHSA-2003-077.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69
- http://www.ethereal.com/appnotes/enpa-sa-00009.html
- http://www.debian.org/security/2003/dsa-313
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:067
References
- http://www.kb.cert.org/vuls/id/641013
- http://www.redhat.com/support/errata/RHSA-2003-077.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A69
- http://www.ethereal.com/appnotes/enpa-sa-00009.html
- http://www.debian.org/security/2003/dsa-313
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:067
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.