CVE-2004-0635: Medium severity Ethereal Group Ethereal vulnerability
Published Jul 8, 2004
·Updated
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
Affected Software
37 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.8.16
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.8.15
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.8.17
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.12
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
redhat Linux Advanced Workstation=2.1
Mandrakesoft Mandrake Linux=9.2
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
Mandrakesoft Mandrake Linux=10.0
Gentoo Linux
redhat Enterprise Linux=3.0
Remediation
Patch Available
Event History
Jul 8, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0635?
CVE-2004-0635 is classified as a denial of service vulnerability that can cause a crash of the Ethereal process.
2
How do I fix CVE-2004-0635?
To fix CVE-2004-0635, update Ethereal to a version newer than 0.10.4 where the vulnerability has been addressed.
3
Which versions of Ethereal are affected by CVE-2004-0635?
CVE-2004-0635 affects Ethereal versions from 0.8.15 to 0.10.4 inclusive.
4
What does CVE-2004-0635 exploit?
CVE-2004-0635 exploits a malformed or missing community string in SNMP traffic to cause an out-of-bounds read.
5
Can CVE-2004-0635 be exploited remotely?
Yes, CVE-2004-0635 can be exploited remotely, allowing attackers to crash the Ethereal application.