CVE-2005-0699: Buffer Overflow
Published Mar 8, 2005
·Updated
Multiple buffer overflows in the dissecta11radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.
Affected Software
27 affected components
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Conectiva Linux=9.0
Conectiva Linux=10.0
Altlinux Alt Linux=compact_2.3
Altlinux Alt Linux=junior_2.3
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=3.0
redhat Enterprise Linux Desktop=4.0
redhat Linux Advanced Workstation=2.1
redhat Linux Advanced Workstation=2.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 8, 2005
CVE Published
via NVD·05:00 AM
Mar 9, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0699?
CVE-2005-0699 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2005-0699?
To fix CVE-2005-0699, update Ethereal to version 0.10.10 or later, or apply any available patches.
3
Which versions of Ethereal are affected by CVE-2005-0699?
Ethereal versions 0.10.3 through 0.10.9 are affected by CVE-2005-0699.
4
Can CVE-2005-0699 be exploited remotely?
Yes, CVE-2005-0699 can be exploited remotely through specially crafted RADIUS authentication packets.
5
What vulnerabilities are similar to CVE-2005-0699?
Similar vulnerabilities to CVE-2005-0699 include other buffer overflow vulnerabilities in network protocol analyzers.