CVE-2005-1461 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 7.12% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ethereal group | ethereal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ethereal 0.10.10 - 'SIP' Protocol Dissector Remote Buffer Overflow | 2005-05-31 |
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000963
- http://www.ethereal.com/appnotes/enpa-sa-00019.html
- http://www.ethereal.com/news/item_20050504_01.html
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-427.html
- http://www.securityfocus.com/bid/13504
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9853
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000963
- http://www.ethereal.com/appnotes/enpa-sa-00019.html
- http://www.ethereal.com/news/item_20050504_01.html
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2005-427.html
- http://www.securityfocus.com/bid/13504
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9853
→ the Explorer · watch your stack · NVD