Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2003-0356 | First vendor Publication | 2003-06-09 |
| Vendor | Cve | Last vendor Modification | 2008-09-10 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Security Protection
| Impacts | Provides administrator access : Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service. |
Detail
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-193 | Off-by-one Error |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:69 | |||
| Oval ID: | oval:org.mitre.oval:def:69 | ||
| Title: | Off-by-one Vulnerabilities in Ethereal 0.9.11 | ||
| Description: | Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2003-0356 |
Version: | 2 |
| Platform(s): | Red Hat Linux 9 |
Product(s): | Ethereal |
| Definition Synopsis: | |||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 6917 | Ethereal TSP Dissector Remote Off-by-one Overflow |
| 6916 | Ethereal SMPP Dissector Remote Off-by-one Overflow |
| 6915 | Ethereal SMB Dissector Remote Off-by-one Overflow |
| 6914 | Ethereal rsync Dissector Remote Off-by-one Overflow |
| 6913 | Ethereal Quake3 Dissector Remote Off-by-one Overflow |
| 6912 | Ethereal Quake2 Dissector Remote Off-by-one Overflow |
| 6911 | Ethereal Quake Dissector Remote Off-by-one Overflow |
| 6910 | Ethereal PPTP Dissector Remote Off-by-one Overflow |
| 6909 | Ethereal OSPF Dissector Remote Off-by-one Overflow |
| 6908 | Ethereal GIOP Gryphon Dissector Remote Off-by-one Overflow |
| 4341 | Ethereal AIM Dissector Remote Off-by-one Overflow |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-11 11:51:14 |
|

CVE-2003-0356
(Critical)







