CVE-2005-0739

Ethereal 0.9.1-0.10.9 - Buffer Overflow in IAPP Dissector

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-0739. PoCs published by Leon Juranic.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Ethereal's IAPP dissector by sending a maliciously crafted UDP packet to port 2313. The PoC constructs a packet with an oversized payload to trigger the crash.

Description

The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Leon Juranic · c++doswindows
https://www.exploit-db.com/exploits/874

This exploit targets a buffer overflow vulnerability in Ethereal's IAPP dissector by sending a maliciously crafted UDP packet to port 2313. The PoC constructs a packet with an oversized payload to trigger the crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Ethereal (versions prior to fix for CVE-2005-0739)
No auth needed
Prerequisites: Network access to target · Target running vulnerable Ethereal version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2005:053
Patch, URL Repurposed x_refsource_confirm
http://www.ethereal.com/appnotes/enpa-sa-00018.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-306.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9687
Patch vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-718
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111066805726551&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12762

Scores

EPSS 0.1702
EPSS Percentile 95.1%

Details

CWE
CWE-189
Status published
Products (1)
ethereal_group/ethereal < 0.10.9
Published May 02, 2005
Tracked Since Feb 18, 2026