vendor:
Ethereal network protocol analyzer
by:
R�mi Denis-Courmont
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Ethereal network protocol analyzer
Affected Version From: Ethereal v0.10.2
Affected Version To: Ethereal v0.10.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
EIGRP Dissector TLV_IP_INT Long IP Address Overflow vulnerability
EIGRP Dissector TLV_IP_INT Long IP Address Overflow vulnerability is a buffer overflow vulnerability in Ethereal v0.10.2. It is triggered by sending a specially crafted packet to the vulnerable system. The packet contains an IP internal routes TLV with a length of 0x39, which is longer than the expected 0x1C. This causes a buffer overflow of up to 29 bytes.
Mitigation:
Upgrade to Ethereal v0.10.3 or later.