CVE-2004-1140: Medium severity ethereal group ethereal vulnerability
Published Dec 31, 2004
·Updated
Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (application hang) and possibly fill available disk space via an invalid RTP timestamp.
Affected Software
26 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.10.0a
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.0
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.9.12
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1140?
CVE-2004-1140 has a CVSS score indicating it can lead to a denial of service due to application hangs.
2
How do I fix CVE-2004-1140?
To fix CVE-2004-1140, upgrade to a patched version of Ethereal beyond 0.10.7.
3
What software versions are affected by CVE-2004-1140?
CVE-2004-1140 affects Ethereal versions 0.9.0 through 0.10.7.
4
What kind of attack does CVE-2004-1140 enable?
CVE-2004-1140 allows remote attackers to cause a denial of service through an invalid RTP timestamp.
5
Can CVE-2004-1140 fill disk space on the affected system?
Yes, exploitation of CVE-2004-1140 could potentially result in filling available disk space.