FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0739

This CVE name corresponds to:

Entered Topic
2005-03-14 ethereal -- multiple protocol dissectors vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0739
Phase Assigned(20050313)

Description

The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.

References

Source Reference
BUGTRAQ 20050312 Ethereal remote buffer overflow #2
MISC http://security.lss.hr/index.php?page=details&ID=LSS-2005-03-05
MISC http://anonsvn.ethereal.com/viewcvs/viewcvs.py?view=rev&rev=13707
CONFIRM http://www.ethereal.com/appnotes/enpa-sa-00018.html
DEBIAN DSA-718
FEDORA FLSA-2006:152922
GENTOO GLSA-200503-16
MANDRAKE MDKSA-2005:053
REDHAT RHSA-2005:306
BID 12762
OVAL oval:org.mitre.oval:def:9687