CVE-2002-0403: Medium severity Ethereal Group Ethereal vulnerability
Published Jun 18, 2002
·Updated
DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed packet that causes Ethereal to enter an infinite loop.
Affected Software
4 affected components
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9_.0
Remediation
Patch Available
Patch Available
Event History
Jun 18, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0403?
CVE-2002-0403 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2002-0403?
To fix CVE-2002-0403, upgrade Ethereal to version 0.9.3 or later.
3
What impact does CVE-2002-0403 have on Ethereal?
CVE-2002-0403 can cause Ethereal to enter an infinite loop, resulting in excessive CPU consumption.
4
Which versions of Ethereal are affected by CVE-2002-0403?
Ethereal versions 0.9.0 to 0.9.2 are affected by CVE-2002-0403.
5
Is there a known exploit for CVE-2002-0403?
Yes, there are known exploits for CVE-2002-0403 that utilize malformed packets to trigger the vulnerability.