CVE-2006-3628

Severity
10.0CRITICAL
EPSS
5.9%
top 9.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 21
Latest updateMay 3

Description

Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages3 packages

Debianwireshark< 0.99.2-1+3
NVDwireshark/wireshark5 versions+4
NVDethereal_group/ethereal18 versions+17

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mg6c-c5w2-g567: Multiple format string vulnerabilities in Wireshark (aka Ethereal) 02022-05-03
OSV
CVE-2006-3628: Multiple format string vulnerabilities in Wireshark (aka Ethereal) 02006-07-21
CVEList
CVE-2006-3628: Multiple format string vulnerabilities in Wireshark (aka Ethereal) 02006-07-18

📋Vendor Advisories

2
Red Hat
security flaw2006-07-17
Debian
CVE-2006-3628: wireshark - Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.9...2006

💬Community

2
Bugzilla
CVE-2006-3628 security flaw2018-08-16
Bugzilla
CVE-2006-3627 Mulitple security issues (CVE-2006-3628 CVE-2006-3629 CVE-2006-3630 CVE-2006-3631 CVE-2006-3632)2006-07-18