CVE-2006-4333: Medium severity Wireshark Wireshark vulnerability
Published Aug 24, 2006
·Updated
The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via malformed packets that cause the Q.2391 dissector to use excessive memory.
Affected Software
5 affected components
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 24, 2006
CVE Published
08:04 PM
Aug 25, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4333?
CVE-2006-4333 is classified as a denial of service vulnerability that can result in resource exhaustion.
2
How do I fix CVE-2006-4333?
To fix CVE-2006-4333, upgrade Wireshark to version 0.99.3 or later.
3
Which versions of Wireshark are affected by CVE-2006-4333?
CVE-2006-4333 affects Wireshark versions 0.10.4, 0.99.2, 0.99.1, 0.10.13, and 0.99.
4
What type of attack is CVE-2006-4333 associated with?
CVE-2006-4333 is associated with remote denial of service attacks using malformed packets.
5
Is there a known exploit for CVE-2006-4333?
While specific exploits may not be publicly documented, CVE-2006-4333 can be exploited through crafted packets that trigger excessive memory use.