CVE-2006-1933: Medium severity Ethereal Group Ethereal vulnerability
Published Apr 25, 2006
·Updated
Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissectors.
Affected Software
16 affected components
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.10.0a
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.10.11
Ethereal Group Ethereal=0.10.12
Ethereal Group Ethereal=0.10.13
Remediation
Patch Available
Event History
Apr 25, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1933?
CVE-2006-1933 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2006-1933?
To fix CVE-2006-1933, you should upgrade to a later version of Ethereal that is not affected by this vulnerability.
3
What versions of Ethereal are affected by CVE-2006-1933?
CVE-2006-1933 affects Ethereal versions from 0.10.0 to 0.10.14 inclusive.
4
Can CVE-2006-1933 be exploited remotely?
Yes, CVE-2006-1933 can be exploited remotely by sending crafted packets to the vulnerable Ethereal application.
5
What type of attack is associated with CVE-2006-1933?
CVE-2006-1933 is associated with denial of service attacks through large or infinite loops in the UMA and BER dissectors.