Vulnerability Note VU#835846
Ethereal fails to properly handle malfored SNMP packets
The Simple Network Management Protocol (SNMP) protocol enables network and system administrators to remotely monitor and configure devices on the network (devices such as switches and routers). Ethereal includes the ability to decode packets containing SNMP data. There is a vulnerability in the way the SNMP dissector decodes SNMP packets containing a malformed or missing community string. By sending a specially crafted SNMP packet or convincing a victim to read a malformed packet trace file, a remote, unauthenticated attacker could cause Ethereal to crash or potentially execute code of the attacker's choice.
A remote, unauthenticated attacker could cause Ethereal to crash or potentially execute code of the attacker's choice.
Upgrade to version 0.10.5 or later.
2) Disable the SNMP protocol dissector from the list by unchecking its "Status" checkbox
However, it is strongly encouraged to upgrade to version 0.10.5 or later.
Systems Affected (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Ethereal||Affected||-||07 Sep 2004|
CVSS Metrics (Learn More)
This vulnerability was reported by the maintainers of Ethereal.
This document was written by Damon Morda.
- CVE IDs: CAN-2004-0635
- Date Public: 06 Jul 2004
- Date First Published: 07 Sep 2004
- Date Last Updated: 07 Sep 2004
- Severity Metric: 8.09
- Document Revision: 7
If you have feedback, comments, or additional information about this vulnerability, please send us email.