Vulnerability Description
Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ethereal Group | Ethereal | 0.8 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc
- http://lists.suse.com/archive/suse-security-announce/2006-May/0004.html
- http://secunia.com/advisories/19769
- http://secunia.com/advisories/19805
- http://secunia.com/advisories/19828
- http://secunia.com/advisories/19839
- http://secunia.com/advisories/19958
- http://secunia.com/advisories/19962
- http://secunia.com/advisories/20117
- http://secunia.com/advisories/20210
- http://secunia.com/advisories/20944
- http://securitytracker.com/id?1015985
- http://support.avaya.com/elmodocs2/security/ASA-2006-128.htm
- http://www.debian.org/security/2006/dsa-1049
- http://www.ethereal.com/appnotes/enpa-sa-00023.htmlPatchURL Repurposed
FAQ
What is CVE-2006-1938?
CVE-2006-1938 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE disse...
How severe is CVE-2006-1938?
CVE-2006-1938 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1938?
Check the references section above for vendor advisories and patch information. Affected products include: Ethereal Group Ethereal.