CVE-2003-1013: Null Pointer Dereference
Published Dec 17, 2003
·Updated
The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.
Affected Software
18 affected components
Ethereal Ethereal<0.10.0
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.1
Remediation
Patch Available
Patch Available
Event History
Dec 17, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 5, 2004
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-1013?
CVE-2003-1013 has a severity level that can lead to a denial of service attack.
2
How do I fix CVE-2003-1013?
To fix CVE-2003-1013, upgrade to Ethereal version 0.10.0 or later.
3
What software is affected by CVE-2003-1013?
CVE-2003-1013 affects multiple versions of Ethereal before 0.10.0, including versions 0.9.1 to 0.9.16.
4
What type of vulnerability is CVE-2003-1013?
CVE-2003-1013 is a null dereference vulnerability that can be triggered by a malformed Q.931.
5
Can CVE-2003-1013 be exploited remotely?
Yes, CVE-2003-1013 can be exploited remotely to cause a crash of the vulnerable Ethereal application.