CVE-2006-4805Wireshark vulnerability

8 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
5.0%
top 10.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateMay 3

Description

epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote attackers to cause a denial of service (memory consumption and crash) via an encoded XOT packet that produces a zero length value when it is decoded.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 0.99.4-1 (bookworm)
Debianwireshark/wireshark< 0.99.4-1+3
NVDwireshark/wireshark9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-369f-gjmm-gjfc: epan/dissectors/packet-xot2022-05-03
OSV
CVE-2006-4805: epan/dissectors/packet-xot2006-10-27

📋Vendor Advisories

2
Red Hat
security flaw2006-10-30
Debian
CVE-2006-4805: wireshark - epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark...2006

💬Community

3
Bugzilla
CVE-2006-4805 security flaw2018-08-16
Bugzilla
CVE-2006-4574 Multiple Wireshark issues (CVE-2006-4805, CVE-2006-5468, CVE-2006-5469, CVE-2006-5740)2006-10-24
Bugzilla
CVE-2006-1932 Multiple ethereal issues (CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, VE-2006-4805, CVE-2006-5468, CVE-2006-542006-05-12