CVE-2003-0927: Buffer Overflow
Published Nov 6, 2003
·Updated
Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.
Affected Software
16 affected components
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 6, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 1, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0927?
CVE-2003-0927 is classified as a high severity vulnerability due to its potential to cause a denial of service and execute arbitrary code.
2
How do I fix CVE-2003-0927?
To fix CVE-2003-0927, upgrade Ethereal to version 0.9.16 or later, which contains the necessary security patches.
3
Which versions of Ethereal are affected by CVE-2003-0927?
CVE-2003-0927 affects Ethereal versions 0.9.15 and earlier.
4
Can CVE-2003-0927 lead to remote code execution?
Yes, CVE-2003-0927 can potentially lead to remote code execution through a heap-based buffer overflow.
5
What exploit methods are associated with CVE-2003-0927?
CVE-2003-0927 may be exploited via specially crafted SOCKS packets, leading to application crashes or arbitrary code execution.