CVE-2006-3632: Buffer Overflow
Published Jul 18, 2006
·Updated
Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the NFS dissector.
Affected Software
41 affected components
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.8.16
Ethereal Group Ethereal=0.10.0a
Ethereal Group Ethereal=0.8.17a
Ethereal Group Ethereal=0.8.20
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.0
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.99.0
Ethereal Group Ethereal=0.10.13
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10.12
Ethereal Group Ethereal=0.10.11
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.10.14
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.8.17
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.9.12
Remediation
Patch Available
Event History
Jul 18, 2006
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3632?
CVE-2006-3632 has a high severity due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2006-3632?
To fix CVE-2006-3632, update Wireshark to a version that is not affected by this vulnerability.
3
What versions of Wireshark are affected by CVE-2006-3632?
CVE-2006-3632 affects Wireshark versions from 0.8.16 to 0.99.0.
4
What are the risks of CVE-2006-3632?
The risks of CVE-2006-3632 include the possibility of remote attackers executing arbitrary code or causing a denial of service.
5
Can CVE-2006-3632 be exploited remotely?
Yes, CVE-2006-3632 can be exploited remotely via specially crafted packets using the NFS dissector.