The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
References
Configurations
Information
Published : 2005-05-01 21:00
Updated : 2017-10-10 18:29
NVD link : CVE-2005-0739
Mitre link : CVE-2005-0739
JSON object : View
CWE
CWE-189
Numeric Errors
Products Affected
ethereal_group
- ethereal