VDB
CVE-2005-0739
CVE-2005-0739
PUBLISHED
CVSS 5 MEDIUM
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
EPSS 7.61% · 94.2th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
7.61%
94.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| ethereal_group | ethereal | 0 |
Timeline
- Mar 13, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- oval:org.mitre.oval:def:9687 vdb
- 12762 vdb
- DSA-718 vendor-advisory
- http://marc.info/?l=bugtraq&m=111066805726551&w=2 technical
- http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707 technical
- http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05 technical
- http://www.redhat.com/support/errata/RHSA-2005-306.html technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:053 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-0739 advisory
- http://www.ethereal.com/appnotes/enpa-sa-00018.html url
- http://www.gentoo.org/security/en/glsa/glsa-200503-16.xml url
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html url