CVE-2002-0401: Null Pointer Dereference
Published Jun 18, 2002
·Updated
SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed packets that cause Ethereal to dereference a NULL pointer.
Affected Software
6 affected components
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9_.0
Ethereal Ethereal<=0.9.3
Debian Debian Linux=2.2
Remediation
Patch Available
Patch Available
Event History
Jun 18, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0401?
CVE-2002-0401 is classified as a high severity vulnerability due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2002-0401?
To fix CVE-2002-0401, update Ethereal to version 0.9.4 or later, which addresses this vulnerability.
3
What versions of Ethereal are affected by CVE-2002-0401?
CVE-2002-0401 affects Ethereal versions 0.9.3 and earlier, including 0.9.2, 0.9.1, and 0.9.0.
4
Can CVE-2002-0401 be exploited remotely?
Yes, CVE-2002-0401 can be exploited remotely through malformed SMB packets.
5
What symptoms indicate an exploitation of CVE-2002-0401?
Symptoms of CVE-2002-0401 exploitation may include application crashes or unexpected behavior when handling network packets.