CVE-2006-3627
published 2006-07-21CVE-2006-3627: Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.27%
87.1th percentile
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.2-1 (bookworm) | wireshark 0.99.2-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 0.99.2-1 | 0.99.2-1 |
| wireshark | wireshark | >= 0 < 0.99.2-1 | 0.99.2-1 |
| wireshark | wireshark | >= 0 < 0.99.2-1 | 0.99.2-1 |
| wireshark | wireshark | >= 0 < 0.99.2-1 | 0.99.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat7.5HIGH
vendor_debian5.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgm4-wx5q-868f: Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0
ghsa_unreviewed·2022-05-03
CVE-2006-3627 [MEDIUM] GHSA-qgm4-wx5q-868f: Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
OSV
CVE-2006-3627: Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0
osv·2006-07-21·CVSS 5.0
CVE-2006-3627 [MEDIUM] CVE-2006-3627: Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
Red Hat
security flaw
vendor_redhat·2006-07-17·CVSS 5.0
CVE-2006-3627 [MEDIUM] security flaw
security flaw
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
Red Hat
security flaw
vendor_redhat·2006-01-03·CVSS 7.5
CVE-2006-0746 [HIGH] security flaw
security flaw
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.
Debian
CVE-2006-3627: wireshark - Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal...
vendor_debian·2006·CVSS 5.0
CVE-2006-3627 [MEDIUM] CVE-2006-3627: wireshark - Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal...
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.99.2-1)
bullseye: resolved (fixed in 0.99.2-1)
forky: resolved (fixed in 0.99.2-1)
sid: resolved (fixed in 0.99.2-1)
trixie: resolved (fixed in 0.99.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-3627 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2006-3627 [MEDIUM] CVE-2006-3627 security flaw
CVE-2006-3627 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
Bugzilla
CVE-2006-0746 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 security flaw
CVE-2006-0746 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.
Bugzilla
CVE-2006-3627 Mulitple security issues (CVE-2006-3628 CVE-2006-3629 CVE-2006-3630 CVE-2006-3631 CVE-2006-3632)
bugzilla·2006-07-18·CVSS 5.0
CVE-2006-3627 [MEDIUM] CVE-2006-3627 Mulitple security issues (CVE-2006-3628 CVE-2006-3629 CVE-2006-3630 CVE-2006-3631 CVE-2006-3632)
CVE-2006-3627 Mulitple security issues (CVE-2006-3628 CVE-2006-3629 CVE-2006-3630 CVE-2006-3631 CVE-2006-3632)
From http://www.wireshark.org/security/wnpa-sec-2006-01.html
Name: Multiple problems in Ethereal® versions 0.8.14 to 0.10.10
Docid: wnpa-sec-2006-01
Date: July 17, 2006
Versions affected: 0.8.16 up to and including 0.99.0
Details
Description
Wireshark 0.99.2 fixes the following vulnerabilities:
* The GSM BSSMAP dissector could crash. Versions affected: 0.10.11. CVE:
CVE-2006-3627
Ilja van Sprundel discovered the following vulnerabilities:
* The ANSI MAP dissector was vulnerable to a format string overflow.
Versions affected: 0.10.0. CVE: CVE-2006-3628
* The Checkpoint FW-1 dissector was vulnerable to a format string overflow.
Versions affected: 0.10.10. CVE: CVE-2006-3628
Bugzilla
CVE-2006-0746 kpdf buffer overflow
bugzilla·2006-03-07·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 kpdf buffer overflow
CVE-2006-0746 kpdf buffer overflow
+++ This bug was initially created as a clone of Bug #184307 +++
The initial fix for CVE-2005-3627 was incomplete in kdegraphics.
The complete patch is attachment 125771
The reproducer is attachment 125772
Here is Chris Evans' original advisory, it has links to various other bad pdf files:
http://scary.beasts.org/security/CESA-2005-003.txt
Discussion:
there's kde-3.5.1 in FC4-update. It's not effected in this new kde version
http://www.kde.org/info/security/advisory-20060202-1.txt
Bugzilla
CVE-2006-0746 kpdf buffer overflow
bugzilla·2006-03-07·CVSS 7.5
CVE-2006-0746 [HIGH] CVE-2006-0746 kpdf buffer overflow
CVE-2006-0746 kpdf buffer overflow
The initial fix for CVE-2005-3627 was incomplete in kdegraphics.
The complete patch is attachment 125771
The reproducer is attachment 125772
Here is Chris Evans' original advisory, it has links to various other bad pdf files:
http://scary.beasts.org/security/CESA-2005-003.txt
Discussion:
it's now fixed in kdegraphics-3.3.1-3.9
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0262.html
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-06·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
+++ This bug was initially created as a clone of Bug #176865 +++
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-01
Bugzilla
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
bugzilla·2006-01-03·CVSS 5.1
CVE-2005-3624 [MEDIUM] [RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
[RHEL4] CVE-2005-3624 Additional xpdf issues (CVE-2005-3625 CVE-2005-3626 CVE-2005-3627)
Chris Evans has discovered some additional issues in xpdf. The patch created by
Ludwig Nussel can be found here:
http://bugs.gentoo.org/show_bug.cgi?id=117481
This patch also contains the previous fixes for CVE-2005-3191, CVE-2005-3192 and
CVE-2005-3193
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0177.html
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-Phttp://rhn.redhat.com/errata/RHSA-2006-0602.htmlhttp://secunia.com/advisories/21078http://secunia.com/advisories/21107http://secunia.com/advisories/21121http://secunia.com/advisories/21204http://secunia.com/advisories/21467http://secunia.com/advisories/21488http://secunia.com/advisories/21598http://secunia.com/advisories/22089http://security.gentoo.org/glsa/glsa-200607-09.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2006-197.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:128http://www.novell.com/linux/security/advisories/2006_20_sr.htmlhttp://www.securityfocus.com/archive/1/440576/100/0/threadedhttp://www.securityfocus.com/bid/19051http://www.vupen.com/english/advisories/2006/2850http://www.wireshark.org/security/wnpa-sec-2006-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27821https://issues.rpath.com/browse/RPL-512https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11307ftp://patches.sgi.com/support/free/security/advisories/20060801-01-Phttp://rhn.redhat.com/errata/RHSA-2006-0602.htmlhttp://secunia.com/advisories/21078http://secunia.com/advisories/21107http://secunia.com/advisories/21121http://secunia.com/advisories/21204http://secunia.com/advisories/21467http://secunia.com/advisories/21488http://secunia.com/advisories/21598http://secunia.com/advisories/22089http://security.gentoo.org/glsa/glsa-200607-09.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2006-197.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:128http://www.novell.com/linux/security/advisories/2006_20_sr.htmlhttp://www.securityfocus.com/archive/1/440576/100/0/threadedhttp://www.securityfocus.com/bid/19051http://www.vupen.com/english/advisories/2006/2850http://www.wireshark.org/security/wnpa-sec-2006-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27821https://issues.rpath.com/browse/RPL-512https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11307
2006-07-21
Published