CVE-2006-1936: Buffer Overflow
Published Apr 25, 2006
·Updated
Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.
Affected Software
18 affected components
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.10.0a
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.10.11
Ethereal Group Ethereal=0.10.12
Ethereal Group Ethereal=0.10.13
Remediation
Patch Available
Event History
Apr 25, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1936?
CVE-2006-1936 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2006-1936?
To fix CVE-2006-1936, update Ethereal to version 0.10.15 or later, which resolves the buffer overflow vulnerability.
3
Who is affected by CVE-2006-1936?
CVE-2006-1936 affects users of Ethereal versions 0.8.5 through 0.10.14.
4
What types of attacks can exploit CVE-2006-1936?
CVE-2006-1936 can be exploited by remote attackers sending specially crafted packets to the telnet dissector.
5
Is CVE-2006-1936 being actively exploited?
As of now, there have been reports of active exploitation of CVE-2006-1936 in the wild.