CVE-2006-4574
published 2006-10-28CVE-2006-4574: Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service…
PriorityP427high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.09%
89.5th percentile
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.4-1 (bookworm) | wireshark 0.99.4-1 (bookworm) |
| wireshark | wireshark | >= 0 < 0.99.4-1 | 0.99.4-1 |
| wireshark | wireshark | >= 0 < 0.99.4-1 | 0.99.4-1 |
| wireshark | wireshark | >= 0 < 0.99.4-1 | 0.99.4-1 |
| wireshark | wireshark | >= 0 < 0.99.4-1 | 0.99.4-1 |
| wireshark | wireshark | 0.10.1 – 0.99.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjqf-4m3m-v7rh: Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0
ghsa_unreviewed·2022-05-03
CVE-2006-4574 [MEDIUM] GHSA-cjqf-4m3m-v7rh: Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
OSV
CVE-2006-4574: Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0
osv·2006-10-28·CVSS 7.5
CVE-2006-4574 [HIGH] CVE-2006-4574: Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Red Hat
security flaw
vendor_redhat·2006-10-30·CVSS 7.5
CVE-2006-4574 [HIGH] security flaw
security flaw
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Debian
CVE-2006-4574: wireshark - Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal...
vendor_debian·2006·CVSS 7.5
CVE-2006-4574 [HIGH] CVE-2006-4574: wireshark - Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal...
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Scope: local
bookworm: resolved (fixed in 0.99.4-1)
bullseye: resolved (fixed in 0.99.4-1)
forky: resolved (fixed in 0.99.4-1)
sid: resolved (fixed in 0.99.4-1)
trixie: resolved (fixed in 0.99.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4574 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-4574 [HIGH] CVE-2006-4574 security flaw
CVE-2006-4574 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
Bugzilla
CVE-2006-4574 Multiple Wireshark issues (CVE-2006-4805, CVE-2006-5468, CVE-2006-5469, CVE-2006-5740)
bugzilla·2006-10-24·CVSS 7.5
CVE-2006-4574 [HIGH] CVE-2006-4574 Multiple Wireshark issues (CVE-2006-4805, CVE-2006-5468, CVE-2006-5469, CVE-2006-5740)
CVE-2006-4574 Multiple Wireshark issues (CVE-2006-4805, CVE-2006-5468, CVE-2006-5469, CVE-2006-5740)
Wireshark 0.99.4 will be fixing several security issues:
CVE-2006-5468
> * NULL point dereference
> The HTTP dissector could dereference a null pointer.
> Fixed in r19022, r19153
> Bug IDs: 1050, 1079
> Versions affected: 0.99.3.
CVE-2006-5469
> The WBXML dissector could crash.
> Fixed in r19560
> Bug IDs: 1134
> Versions affected: 0.10.11 to 0.99.3.
CVE-2006-5470
> * OOB memory read
> The LDAP dissector (and possibly others) could crash.
> Fixed in r19154
> Bug IDs: 1079
> Versions affected: 0.99.3.
CVE-2006-4805
> * Basic DoS (it crashes, that's it)
> The XOT dissector could attempt to allocate a large amount of
> memory and crash.
> Fixed in r19365
> Bug IDs: 1133
> Versions affe
Bugzilla
CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, VE-2006-4805, CVE-2006-5468, CVE-2006-54
bugzilla·2006-05-12·CVSS 10.0
CVE-2006-1932 [CRITICAL] CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, VE-2006-4805, CVE-2006-5468, CVE-2006-54
CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, VE-2006-4805, CVE-2006-5468, CVE-2006-5469, CVE-2006-5740, CVE-2006-4574)
+++ This bug was initially created as a clone of Bug #189906 +++
Ethereal 0.99.0 has been released which fixes multiple issues. The release
information can be found here:
http://www.ethereal.com/appnotes/enpa-sa-00023.html
These issues should also affect RHEL2 and RHEL3
-- Additional comment from [email protected] on 2006-05-03 12:28 EST --
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the
CWE
Reachable Assertion
mitre_cwe·CVSS 7.5
[HIGH] CWE-617 Reachable Assertion
CWE-617: Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
While assertion is good for catching logic errors and reducing the chances of reaching more serious vulnerability conditions, it can still lead to a denial of service. For example, if a server handles multiple simultaneous connections, and an assert() occurs in one single connection that causes all other connections to be dropped, this is a reachable assertion that leads to a denial of service.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. An attacker that can trigger an assert statement can still lead
CWE
Off-by-one Error
mitre_cwe
CWE-193 Off-by-one Error
CWE-193: Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Instability. This weakness will generally lead to undefined behavior and therefore crashes. In the case of overflows involving loop index variables, the likelihood of infinite loops is also high.
Scope: Integrity. Impact: Modify Memory. If the value in question is important to data (as opposed to flow), simple data corruption has occurred. Also, if the wrap around results in other conditions such as buffer overflows, further memory corruption may occ
ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://secunia.com/advisories/22590http://secunia.com/advisories/22659http://secunia.com/advisories/22672http://secunia.com/advisories/22692http://secunia.com/advisories/22797http://secunia.com/advisories/22841http://secunia.com/advisories/22929http://secunia.com/advisories/23096http://securitytracker.com/id?1017129http://support.avaya.com/elmodocs2/security/ASA-2006-255.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:195http://www.novell.com/linux/security/advisories/2006_65_ethereal.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0726.htmlhttp://www.securityfocus.com/archive/1/450307/100/0/threadedhttp://www.securityfocus.com/bid/20762http://www.us.debian.org/security/2006/dsa-1201http://www.vupen.com/english/advisories/2006/4220http://www.wireshark.org/security/wnpa-sec-2006-03.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/29844https://issues.rpath.com/browse/RPL-746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9740ftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://secunia.com/advisories/22590http://secunia.com/advisories/22659http://secunia.com/advisories/22672http://secunia.com/advisories/22692http://secunia.com/advisories/22797http://secunia.com/advisories/22841http://secunia.com/advisories/22929http://secunia.com/advisories/23096http://securitytracker.com/id?1017129http://support.avaya.com/elmodocs2/security/ASA-2006-255.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:195http://www.novell.com/linux/security/advisories/2006_65_ethereal.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0726.htmlhttp://www.securityfocus.com/archive/1/450307/100/0/threadedhttp://www.securityfocus.com/bid/20762http://www.us.debian.org/security/2006/dsa-1201http://www.vupen.com/english/advisories/2006/4220http://www.wireshark.org/security/wnpa-sec-2006-03.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/29844https://issues.rpath.com/browse/RPL-746https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9740
2006-10-28
Published