CVE-2004-0365: Null Pointer Dereference
Published Mar 25, 2004
·Updated
The dissectattributevaluepairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
Affected Software
25 affected components
Ethereal Ethereal>=0.8.13<0.10.3
Ethereal Group Ethereal=0.8.13
Ethereal Group Ethereal=0.8.14
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Event History
Mar 25, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0365?
CVE-2004-0365 has a severity rating that indicates a denial of service vulnerability allowing crashes due to null dereference.
2
How do I fix CVE-2004-0365?
To fix CVE-2004-0365, update Ethereal to version 0.10.3 or later to eliminate the vulnerability.
3
What software versions are affected by CVE-2004-0365?
CVE-2004-0365 affects Ethereal versions from 0.8.13 to 0.10.2, as well as specific earlier versions.
4
What type of attack can exploit CVE-2004-0365?
CVE-2004-0365 can be exploited by sending a malformed RADIUS packet, causing a denial of service.
5
Is there a workaround for CVE-2004-0365 if I cannot update immediately?
A temporary workaround for CVE-2004-0365 is to restrict network access to Ethereal or monitor for malformed packets.