5
CVSSv2

CVE-2004-0635

Published: 06/12/2004 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SNMP dissector in Ethereal 0.8.15 up to and including 0.10.4 allows remote malicious users to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.

Vulnerable Product Search on Vulmon Subscribe to Product

ethereal group ethereal 0.10.1

ethereal group ethereal 0.9.2

ethereal group ethereal 0.9.6

ethereal group ethereal 0.8.16

ethereal group ethereal 0.9.5

ethereal group ethereal 0.8.19

ethereal group ethereal 0.10.2

ethereal group ethereal 0.8.18

ethereal group ethereal 0.9.14

ethereal group ethereal 0.9.15

ethereal group ethereal 0.9.10

ethereal group ethereal 0.9.8

ethereal group ethereal 0.10.3

ethereal group ethereal 0.10.4

ethereal group ethereal 0.9.16

ethereal group ethereal 0.8.15

ethereal group ethereal 0.9.3

ethereal group ethereal 0.10

ethereal group ethereal 0.9.13

ethereal group ethereal 0.9.9

ethereal group ethereal 0.9.11

ethereal group ethereal 0.9.7

ethereal group ethereal 0.9.4

ethereal group ethereal 0.9.1

ethereal group ethereal 0.8.17

ethereal group ethereal 0.9

ethereal group ethereal 0.9.12

redhat enterprise linux 3.0

redhat enterprise linux 2.1

redhat linux advanced workstation 2.1

mandrakesoft mandrake linux 9.2

mandrakesoft mandrake linux 10.0

gentoo linux

Vendor Advisories

Synopsis ethereal security update Type/Severity Security Advisory: Moderate Topic Updated Ethereal packages that fix various security vulnerabilities are nowavailable Description Ethereal is a program for monitoring network trafficThe SNMP dissector in Ethereal releases 0815 through 01 ...
Several denial of service vulnerabilities were discovered in ethereal, a network traffic analyzer These vulnerabilities are described in the ethereal advisory "enpa-sa-00015" Of these, only one (CAN-2004-0635) affects the version of ethereal in Debian woody This vulnerability could be exploited by a remote attacker to crash ethereal with an inva ...