CVE-2003-0356

CRITICAL

Ethereal <0.9.11 - DoS/Arbitrary Code Execution

Title source: llm
STIX 2.1

Description

Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.

Scores

CVSS v3 9.8
EPSS 0.2841
EPSS Percentile 96.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-193
Status published
Products (1)
ethereal/ethereal < 0.9.12
Published Jun 09, 2003
Tracked Since Feb 18, 2026