CVE-2006-4574: High severity Wireshark Wireshark vulnerability
Published Oct 28, 2006
·Updated
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Affected Software
11 affected components
Wireshark Wireshark=0.7.9
Wireshark Wireshark=0.8.16
Wireshark Wireshark=0.9.10
Wireshark Wireshark=0.10
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark>=0.10.1<=0.99.3
Event History
Oct 28, 2006
CVE Published
12:07 AM
Data Sourced
via NVD·12:07 AM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4574?
CVE-2006-4574 is classified as a denial of service vulnerability.
2
How do I fix CVE-2006-4574?
To fix CVE-2006-4574, upgrade Wireshark to a version later than 0.99.3 or apply the relevant patches.
3
Which versions of Wireshark are affected by CVE-2006-4574?
CVE-2006-4574 affects Wireshark versions from 0.10.1 through 0.99.3.
4
What type of attack can be executed using CVE-2006-4574?
An attacker can exploit CVE-2006-4574 to cause a denial of service by triggering a crash in Wireshark.
5
What causes the vulnerability in CVE-2006-4574?
The vulnerability in CVE-2006-4574 is caused by an off-by-one error in the MIME Multipart dissector.