First published: Tue Dec 17 2002(Updated: )
Ethereal 0.9.7 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed packets to the (1) LMP, (2) PPP, or (3) TDS dissectors, possibly related to a missing field for EndVerifyAck messages.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ethereal Group Ethereal | <=0.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1356 is classified as a denial of service vulnerability that may allow remote attackers to cause crashes and potentially execute arbitrary code.
To fix CVE-2002-1356, update to a later version of Ethereal that is not vulnerable, specifically any version after 0.9.7.
Ethereal versions 0.9.7 and earlier are affected by CVE-2002-1356.
CVE-2002-1356 can be exploited through malformed packets sent to the LMP, PPP, or TDS dissectors.
The impact of CVE-2002-1356 includes potential denial of service and the risk of arbitrary code execution on vulnerable systems.