CVE-2005-1465: Medium severity Ethereal Group Ethereal vulnerability
Published May 5, 2005
·Updated
Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).
Affected Software
34 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.8
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.8.13
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.8.15
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.8.14
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.12
Remediation
Patch Available
Patch Available
Event History
May 5, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1465?
CVE-2005-1465 is classified as a denial of service vulnerability due to a long loop in the NCP dissector of Ethereal.
2
How do I fix CVE-2005-1465?
To fix CVE-2005-1465, upgrade to Ethereal version 0.10.11 or later, where the vulnerability has been addressed.
3
Which versions of Ethereal are affected by CVE-2005-1465?
CVE-2005-1465 affects Ethereal versions prior to 0.10.11, including several versions in the 0.8, 0.9, and 0.10 series.
4
What can attackers do with CVE-2005-1465?
Attackers can exploit CVE-2005-1465 to create a denial of service condition, causing the application to enter a long processing loop.
5
Is there a mitigation strategy for CVE-2005-1465 until a patch is applied?
The best mitigation for CVE-2005-1465 is to restrict access to Ethereal or not use affected versions until an upgrade can be performed.