Vulnerability Description
Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wireshark | Wireshark | >= 0.10.1, <= 0.99.3 |
Related Weaknesses (CWE)
References
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-PBroken Link
- http://secunia.com/advisories/22590Broken LinkVendor Advisory
- http://secunia.com/advisories/22659Broken Link
- http://secunia.com/advisories/22672Broken Link
- http://secunia.com/advisories/22692Broken Link
- http://secunia.com/advisories/22797Broken Link
- http://secunia.com/advisories/22841Broken Link
- http://secunia.com/advisories/22929Broken Link
- http://secunia.com/advisories/23096Broken Link
- http://securitytracker.com/id?1017129Broken LinkThird Party AdvisoryVDB Entry
- http://support.avaya.com/elmodocs2/security/ASA-2006-255.htmThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:195Third Party Advisory
- http://www.novell.com/linux/security/advisories/2006_65_ethereal.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2006-0726.htmlBroken Link
- http://www.securityfocus.com/archive/1/450307/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2006-4574?
CVE-2006-4574 is a vulnerability with a CVSS score of 7.5 (HIGH). Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an...
How severe is CVE-2006-4574?
CVE-2006-4574 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4574?
Check the references section above for vendor advisories and patch information. Affected products include: Wireshark Wireshark.