CVE-2003-0356: Critical severity Ethereal Group Ethereal vulnerability
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvbgetnstringz and tvbgetnstringz0 functions.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0356?
CVE-2003-0356 has a medium severity rating primarily due to its potential for denial of service and execution of arbitrary code.
How do I fix CVE-2003-0356?
To mitigate CVE-2003-0356, ensure you upgrade Ethereal to version 0.9.12 or later, as this version addresses the vulnerability.
What types of attacks can exploit CVE-2003-0356?
CVE-2003-0356 can be exploited through crafted packets targeting the affected dissectors, potentially leading to denial of service or arbitrary code execution.
Which versions of Ethereal are affected by CVE-2003-0356?
Ethereal versions up to and including 0.9.11 are affected by CVE-2003-0356.
What components of Ethereal are impacted by CVE-2003-0356?
CVE-2003-0356 impacts multiple dissectors within Ethereal including those for AIM, GIOP Gryphon, OSPF, and several others.