5
CVSSv2

CVE-2006-4574

Published: 28/10/2006 Updated: 15/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 up to and including 0.99.3 allows remote malicious users to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark

Vendor Advisories

Debian Bug report logs - #396258 multiple wireshark security issues fixed in 0994 Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 30 Oct 2006 20:48:12 UTC Severity ...
Several remote vulnerabilities have been discovered in the Ethereal network scanner The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4574 It was discovered that the MIME multipart dissector is vulnerable to denial of service caused by an off-by-one overflow CVE-2006-4805 It was discovered t ...