CVE-2003-0356

CRITICAL

Ethereal <0.9.11 - DoS/Arbitrary Code Execution

Title source: llm
STIX 2.1

Description

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

References (6)

Core 6
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/641013
Broken Link vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-077.html
Broken Link, Patch, Vendor Advisory x_refsource_confirm
http://www.ethereal.com/appnotes/enpa-sa-00009.html
Broken Link, Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2003/dsa-313
Third Party Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2003:067

Scores

CVSS v3 9.8
EPSS 0.0957
EPSS Percentile 94.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-193
Status published
Products (1)
ethereal/ethereal < 0.9.12
Published Jun 09, 2003
Tracked Since Feb 18, 2026