CVE-2005-2367

Ethereal <0.10.11 - RCE

Title source: llm

Description

Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.

Exploits (1)

exploitdb WORKING POC VERIFIED
by vade79 · cremotelinux
https://www.exploit-db.com/exploits/1139

Scores

EPSS 0.2391
EPSS Percentile 96.0%

Details

Status published
Products (25)
ethereal_group/ethereal 0.9.4
ethereal_group/ethereal 0.9.5
ethereal_group/ethereal 0.9.6
ethereal_group/ethereal 0.9.7
ethereal_group/ethereal 0.9.8
ethereal_group/ethereal 0.9.9
ethereal_group/ethereal 0.9.10
ethereal_group/ethereal 0.9.11
ethereal_group/ethereal 0.9.12
ethereal_group/ethereal 0.9.13
... and 15 more
Published Aug 10, 2005
Tracked Since Feb 18, 2026