CVE-2002-1356: High severity ethereal group ethereal vulnerability
Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1356?
CVE-2002-1356 is classified as a denial of service vulnerability that may allow remote attackers to cause crashes and potentially execute arbitrary code.
How do I fix CVE-2002-1356?
To fix CVE-2002-1356, update to a later version of Ethereal that is not vulnerable, specifically any version after 0.9.7.
Which versions of Ethereal are affected by CVE-2002-1356?
Ethereal versions 0.9.7 and earlier are affected by CVE-2002-1356.
What types of packets can exploit CVE-2002-1356?
CVE-2002-1356 can be exploited through malformed packets sent to the LMP, PPP, or TDS dissectors.
What impact does CVE-2002-1356 have on system security?
The impact of CVE-2002-1356 includes potential denial of service and the risk of arbitrary code execution on vulnerable systems.