CVE-2003-0081: High severity Ethereal Group Ethereal vulnerability
Published Mar 18, 2003
·Updated
Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.
Affected Software
11 affected components
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.9.0
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 18, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0081?
CVE-2003-0081 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2003-0081?
To fix CVE-2003-0081, you should update to a version of Ethereal that is not vulnerable, specifically versions later than 0.9.9.
3
What versions of Ethereal are affected by CVE-2003-0081?
CVE-2003-0081 affects Ethereal versions from 0.8.7 to 0.9.9.
4
What type of vulnerability is CVE-2003-0081?
CVE-2003-0081 is categorized as a format string vulnerability affecting the SOCKS dissector.
5
Can CVE-2003-0081 be exploited remotely?
Yes, CVE-2003-0081 can be exploited remotely through specially crafted SOCKS packets.