CVE-2005-2364: Null Pointer Dereference
Published Aug 10, 2005
·Updated
Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 allows remote attackers to cause a denial of service (application crash) via certain packets that cause a null pointer dereference.
Affected Software
30 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.8.20
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.0
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10.11
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.9.12
Remediation
Patch Available
Patch Available
Event History
Aug 10, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2364?
CVE-2005-2364 has been classified with a moderate severity level due to its potential to cause application crashes.
2
How do I fix CVE-2005-2364?
To fix CVE-2005-2364, it is recommended to upgrade Ethereal to a version newer than 0.10.11.
3
What versions of Ethereal are affected by CVE-2005-2364?
CVE-2005-2364 affects multiple versions of Ethereal, including 0.8.20 to 0.10.11.
4
Can CVE-2005-2364 be exploited remotely?
Yes, CVE-2005-2364 can be exploited remotely by sending specially crafted packets.
5
What type of attack is CVE-2005-2364 associated with?
CVE-2005-2364 is associated with denial of service attacks that result in application crashes.