peter bassill · operator
$ cve CVE-2005-0739 JSON

CVE-2005-0739 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS7.61% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
ethereal groupethereal

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD