CVE-2004-1142: Medium severity ethereal group ethereal vulnerability
Published Dec 15, 2004
·Updated
Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
Affected Software
61 affected components
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.7
SGI ProPack=3.0
Conectiva Linux=9.0
Conectiva Linux=10.0
Altlinux Alt Linux=2.3
Altlinux Alt Linux=2.3
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
Debian Debian Linux=3.0
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=3.0
redhat Linux Advanced Workstation=2.1
redhat Linux Advanced Workstation=2.1
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.0
SUSE SuSE Linux=8.1
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 15, 2004
CVE Published
via NVD·05:00 AM
Dec 31, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1142?
CVE-2004-1142 is classified as a denial of service vulnerability, leading to high CPU consumption.
2
How do I fix CVE-2004-1142?
To fix CVE-2004-1142, upgrade to a version of Ethereal that is not affected, specifically any version later than 0.10.7.
3
What versions of Ethereal are affected by CVE-2004-1142?
CVE-2004-1142 affects Ethereal versions from 0.9.0 through 0.10.7.
4
Can CVE-2004-1142 be exploited remotely?
Yes, CVE-2004-1142 can be exploited remotely by sending a malformed SMB packet.
5
What are the potential impacts of CVE-2004-1142?
Exploitation of CVE-2004-1142 can lead to service interruption due to excessive CPU consumption.