CVE-2006-3628

Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
References
Link Resource
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
http://rhn.redhat.com/errata/RHSA-2006-0602.html
http://secunia.com/advisories/21078 Patch Vendor Advisory
http://secunia.com/advisories/21107 Patch Vendor Advisory
http://secunia.com/advisories/21121 Vendor Advisory
http://secunia.com/advisories/21204 Vendor Advisory
http://secunia.com/advisories/21249 Vendor Advisory
http://secunia.com/advisories/21467 Vendor Advisory
http://secunia.com/advisories/21488 Vendor Advisory
http://secunia.com/advisories/21598 Vendor Advisory
http://secunia.com/advisories/22089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200607-09.xml
http://securitytracker.com/id?1016532
http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm
http://www.debian.org/security/2006/dsa-1127
http://www.mandriva.com/security/advisories?name=MDKSA-2006:128
http://www.novell.com/linux/security/advisories/2006_20_sr.html
http://www.osvdb.org/27362
http://www.osvdb.org/27363
http://www.osvdb.org/27364
http://www.osvdb.org/27369
http://www.securityfocus.com/archive/1/440576/100/0/threaded
http://www.securityfocus.com/bid/19051 Patch
http://www.vupen.com/english/advisories/2006/2850 Vendor Advisory
http://www.wireshark.org/security/wnpa-sec-2006-01.html Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/27822
https://exchange.xforce.ibmcloud.com/vulnerabilities/27823
https://exchange.xforce.ibmcloud.com/vulnerabilities/27824
https://exchange.xforce.ibmcloud.com/vulnerabilities/27825
https://exchange.xforce.ibmcloud.com/vulnerabilities/27828
https://issues.rpath.com/browse/RPL-512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9175
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P
http://rhn.redhat.com/errata/RHSA-2006-0602.html
http://secunia.com/advisories/21078 Patch Vendor Advisory
http://secunia.com/advisories/21107 Patch Vendor Advisory
http://secunia.com/advisories/21121 Vendor Advisory
http://secunia.com/advisories/21204 Vendor Advisory
http://secunia.com/advisories/21249 Vendor Advisory
http://secunia.com/advisories/21467 Vendor Advisory
http://secunia.com/advisories/21488 Vendor Advisory
http://secunia.com/advisories/21598 Vendor Advisory
http://secunia.com/advisories/22089 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200607-09.xml
http://securitytracker.com/id?1016532
http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm
http://www.debian.org/security/2006/dsa-1127
http://www.mandriva.com/security/advisories?name=MDKSA-2006:128
http://www.novell.com/linux/security/advisories/2006_20_sr.html
http://www.osvdb.org/27362
http://www.osvdb.org/27363
http://www.osvdb.org/27364
http://www.osvdb.org/27369
http://www.securityfocus.com/archive/1/440576/100/0/threaded
http://www.securityfocus.com/bid/19051 Patch
http://www.vupen.com/english/advisories/2006/2850 Vendor Advisory
http://www.wireshark.org/security/wnpa-sec-2006-01.html Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/27822
https://exchange.xforce.ibmcloud.com/vulnerabilities/27823
https://exchange.xforce.ibmcloud.com/vulnerabilities/27824
https://exchange.xforce.ibmcloud.com/vulnerabilities/27825
https://exchange.xforce.ibmcloud.com/vulnerabilities/27828
https://issues.rpath.com/browse/RPL-512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9175
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ethereal_group:ethereal:0.10:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.0a:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.3:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.4:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.5:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.6:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.7:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.8:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.9:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.10:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.11:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.12:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.13:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.10.14:*:*:*:*:*:*:*
cpe:2.3:a:ethereal_group:ethereal:0.99.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.4:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.13:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P - () ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P -
References () http://rhn.redhat.com/errata/RHSA-2006-0602.html - () http://rhn.redhat.com/errata/RHSA-2006-0602.html -
References () http://secunia.com/advisories/21078 - Patch, Vendor Advisory () http://secunia.com/advisories/21078 - Patch, Vendor Advisory
References () http://secunia.com/advisories/21107 - Patch, Vendor Advisory () http://secunia.com/advisories/21107 - Patch, Vendor Advisory
References () http://secunia.com/advisories/21121 - Vendor Advisory () http://secunia.com/advisories/21121 - Vendor Advisory
References () http://secunia.com/advisories/21204 - Vendor Advisory () http://secunia.com/advisories/21204 - Vendor Advisory
References () http://secunia.com/advisories/21249 - Vendor Advisory () http://secunia.com/advisories/21249 - Vendor Advisory
References () http://secunia.com/advisories/21467 - Vendor Advisory () http://secunia.com/advisories/21467 - Vendor Advisory
References () http://secunia.com/advisories/21488 - Vendor Advisory () http://secunia.com/advisories/21488 - Vendor Advisory
References () http://secunia.com/advisories/21598 - Vendor Advisory () http://secunia.com/advisories/21598 - Vendor Advisory
References () http://secunia.com/advisories/22089 - Vendor Advisory () http://secunia.com/advisories/22089 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200607-09.xml - () http://security.gentoo.org/glsa/glsa-200607-09.xml -
References () http://securitytracker.com/id?1016532 - () http://securitytracker.com/id?1016532 -
References () http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm - () http://support.avaya.com/elmodocs2/security/ASA-2006-197.htm -
References () http://www.debian.org/security/2006/dsa-1127 - () http://www.debian.org/security/2006/dsa-1127 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:128 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:128 -
References () http://www.novell.com/linux/security/advisories/2006_20_sr.html - () http://www.novell.com/linux/security/advisories/2006_20_sr.html -
References () http://www.osvdb.org/27362 - () http://www.osvdb.org/27362 -
References () http://www.osvdb.org/27363 - () http://www.osvdb.org/27363 -
References () http://www.osvdb.org/27364 - () http://www.osvdb.org/27364 -
References () http://www.osvdb.org/27369 - () http://www.osvdb.org/27369 -
References () http://www.securityfocus.com/archive/1/440576/100/0/threaded - () http://www.securityfocus.com/archive/1/440576/100/0/threaded -
References () http://www.securityfocus.com/bid/19051 - Patch () http://www.securityfocus.com/bid/19051 - Patch
References () http://www.vupen.com/english/advisories/2006/2850 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/2850 - Vendor Advisory
References () http://www.wireshark.org/security/wnpa-sec-2006-01.html - Patch () http://www.wireshark.org/security/wnpa-sec-2006-01.html - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27822 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27822 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27823 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27823 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27824 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27824 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27825 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27825 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27828 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27828 -
References () https://issues.rpath.com/browse/RPL-512 - () https://issues.rpath.com/browse/RPL-512 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9175 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9175 -

Information

Published : 2006-07-21 14:03

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3628

Mitre link : CVE-2006-3628

CVE.ORG link : CVE-2006-3628


JSON object : View

Products Affected

wireshark

  • wireshark

ethereal_group

  • ethereal
CWE
CWE-134

Use of Externally-Controlled Format String