CVE-2004-0504: Medium severity Ethereal Group Ethereal vulnerability
Published Jun 3, 2004
·Updated
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
Affected Software
5 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.10.3
SGI ProPack=2.4
SGI ProPack=3.0
Remediation
Patch Available
Patch Available
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0504?
CVE-2004-0504 is classified as a denial of service vulnerability that can cause Ethereal to crash.
2
How do I fix CVE-2004-0504?
To fix CVE-2004-0504, upgrade Ethereal to version 0.10.4 or later.
3
Which versions of Ethereal are affected by CVE-2004-0504?
Ethereal versions 0.10.1, 0.10.2, and 0.10.3 are affected by CVE-2004-0504.
4
What attack vectors are associated with CVE-2004-0504?
CVE-2004-0504 can be exploited through specially crafted SIP messages sent between Hotsip servers and clients.
5
Is there any workaround for CVE-2004-0504?
The most effective workaround for CVE-2004-0504 is to avoid using affected versions of Ethereal until an upgrade can be performed.