CVE-2005-2367

Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.
References
Link Resource
http://secunia.com/advisories/16225/
http://secunia.com/advisories/17102
http://www.debian.org/security/2005/dsa-853
http://www.ethereal.com/appnotes/enpa-sa-00020.html Patch URL Repurposed
http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml Patch
http://www.idefense.com/application/poi/display?id=289&type=vulnerabilities Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:131 Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://www.novell.com/linux/security/advisories/2005_19_sr.html
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
http://www.redhat.com/support/errata/RHSA-2005-687.html
http://www.securityfocus.com/bid/14399
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10765
http://secunia.com/advisories/16225/
http://secunia.com/advisories/17102
http://www.debian.org/security/2005/dsa-853
http://www.ethereal.com/appnotes/enpa-sa-00020.html Patch URL Repurposed
http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml Patch
http://www.idefense.com/application/poi/display?id=289&type=vulnerabilities Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:131 Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://www.novell.com/linux/security/advisories/2005_19_sr.html
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
http://www.redhat.com/support/errata/RHSA-2005-687.html
http://www.securityfocus.com/bid/14399
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10765
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ethereal_group:ethereal:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.9:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.11:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.12:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.13:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.14:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.15:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.9.16:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.3:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.4:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.5:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.6:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.7:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.8:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.9:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.10:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.11:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://secunia.com/advisories/16225/ - () http://secunia.com/advisories/16225/ -
References () http://secunia.com/advisories/17102 - () http://secunia.com/advisories/17102 -
References () http://www.debian.org/security/2005/dsa-853 - () http://www.debian.org/security/2005/dsa-853 -
References () http://www.ethereal.com/appnotes/enpa-sa-00020.html - Patch, URL Repurposed () http://www.ethereal.com/appnotes/enpa-sa-00020.html - Patch, URL Repurposed
References () http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml - Patch () http://www.gentoo.org/security/en/glsa/glsa-200507-27.xml - Patch
References () http://www.idefense.com/application/poi/display?id=289&type=vulnerabilities - Vendor Advisory () http://www.idefense.com/application/poi/display?id=289&type=vulnerabilities - Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDKSA-2005:131 - Patch, Vendor Advisory () http://www.mandriva.com/security/advisories?name=MDKSA-2005:131 - Patch, Vendor Advisory
References () http://www.novell.com/linux/security/advisories/2005_18_sr.html - () http://www.novell.com/linux/security/advisories/2005_18_sr.html -
References () http://www.novell.com/linux/security/advisories/2005_19_sr.html - () http://www.novell.com/linux/security/advisories/2005_19_sr.html -
References () http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html - () http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html -
References () http://www.redhat.com/support/errata/RHSA-2005-687.html - () http://www.redhat.com/support/errata/RHSA-2005-687.html -
References () http://www.securityfocus.com/bid/14399 - () http://www.securityfocus.com/bid/14399 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10765 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10765 -

14 Feb 2024, 01:17

Type Values Removed Values Added
References (CONFIRM) http://www.ethereal.com/appnotes/enpa-sa-00020.html - Patch (CONFIRM) http://www.ethereal.com/appnotes/enpa-sa-00020.html - Patch, URL Repurposed

Information

Published : 2005-08-10 04:00

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2367

Mitre link : CVE-2005-2367

CVE.ORG link : CVE-2005-2367


JSON object : View

Products Affected

ethereal_group

  • ethereal