CVE-2005-0739
Last modified
CVE-2005-0739 is a vulnerability of currently unknown severity. The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.. EPSS estimates a 7.61% chance of exploitation in the next 30 days.
Description
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ethereal Group | Ethereal | <= 0.10.9 |
References
- http://www.ethereal.com/appnotes/enpa-sa-00018.htmlPatch, URL Repurposed
- http://www.ethereal.com/appnotes/enpa-sa-00018.htmlPatch, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0739?
How severe is CVE-2005-0739?
How do I fix CVE-2005-0739?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0733PY Software Active Webcam WebServer (webcam.exe) 5.5 allows …
- CVE-2005-0734PY Software Active Webcam WebServer (webcam.exe) 5.5 allows …
- CVE-2005-0735newsscript.pl for NewsScript allows remote attackers to gain…
- CVE-2005-0736Integer overflow in sys_epoll_wait in eventpoll.c for Linux …
- CVE-2005-0737Buffer overflow in Yahoo! Messenger allows remote attackers …
- CVE-2005-0738Stack consumption vulnerability in Microsoft Exchange Server…
- CVE-2005-0740The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows re…
- CVE-2005-0741Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB…
- CVE-2005-0742Cross-site scripting (XSS) vulnerability in Sun Java System …
- CVE-2005-0743The custom avatar uploading feature (uploader.php) for XOOPS…
- CVE-2005-0744The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows…
- CVE-2005-0745UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows…
Are you affected by CVE-2005-0739?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
