CVE-2005-1457: Medium severity Ethereal Group Ethereal vulnerability
Published May 5, 2005
·Updated
Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSMMAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).
Affected Software
34 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.8
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.8.13
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.8.15
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.8.14
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.12
Remediation
Patch Available
Event History
May 5, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1457?
CVE-2005-1457 is classified as a denial of service vulnerability.
2
How do I fix CVE-2005-1457?
To fix CVE-2005-1457, you should upgrade to Ethereal version 0.10.11 or later.
3
Which versions of Ethereal are affected by CVE-2005-1457?
The affected versions of Ethereal include 0.10.1, 0.8, 0.9.2, and others up to 0.10.10.
4
What types of attacks does CVE-2005-1457 enable?
CVE-2005-1457 allows remote attackers to cause a denial of service which can crash the application.
5
Is CVE-2005-1457 a known vulnerability?
Yes, CVE-2005-1457 is a documented vulnerability affecting earlier versions of the Ethereal network protocol analyzer.