CVE-2004-0367: Medium severity Ethereal Group Ethereal vulnerability
Published Mar 25, 2004
·Updated
Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.
Affected Software
24 affected components
Ethereal Group Ethereal=0.8.13
Ethereal Group Ethereal=0.8.14
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Remediation
Patch Available
Event History
Mar 25, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0367?
CVE-2004-0367 has a moderate severity level as it can cause a denial of service by crashing the application.
2
How do I fix CVE-2004-0367?
To fix CVE-2004-0367, upgrade to Ethereal version 0.10.3 or later, which addresses this vulnerability.
3
Which versions of Ethereal are affected by CVE-2004-0367?
CVE-2004-0367 affects Ethereal versions from 0.8.14 up to 0.10.2.
4
What type of attack is CVE-2004-0367 associated with?
CVE-2004-0367 is associated with a remote denial of service attack.
5
Can I mitigate CVE-2004-0367 without upgrading?
Mitigating CVE-2004-0367 without upgrading is not possible; the best approach is to apply the available patch or upgrade.