CVE-2003-0927Improper Restriction of Operations within the Bounds of a Memory Buffer in Group Ethereal

7 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.4%
top 14.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 1
Latest updateApr 29

Description

Heap-based buffer overflow in Ethereal 0.9.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SOCKS dissector.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDethereal_group/ethereal16 versions+15

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g8cm-56x9-whp3: Heap-based buffer overflow in Ethereal 02022-04-29
CVEList
CVE-2003-0927: Heap-based buffer overflow in Ethereal 02003-11-06

💥Exploits & PoCs

1
Exploit-DB
Adobe Acrobat/Reader < 7.1.1/8.1.3/9.1 - Collab getIcon Universal2009-09-03

📋Vendor Advisories

1
Red Hat
security flaw2003-11-03

💬Community

2
Bugzilla
CVE-2003-0927 security flaw2018-08-16
Bugzilla
CAN-2003-0925/6/7 Ethereal 0.9.13 has three exploitable security issues2003-11-05
CVE-2003-0927 — Ethereal Group Ethereal vulnerability | cvebase