CVE-2006-3628
ethereal - several
EPSS 5.9%
Description
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
How to fix CVE-2006-3628
To remediate CVE-2006-3628, upgrade the affected package to a fixed version below.
- Debian/ethereal—upgrade to 0.10.10-2sarge6 or later
- Debian/wireshark—upgrade to 0.99.2-1 or later
Is CVE-2006-3628 being exploited?
Moderate — EPSS is 5.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 0.10.10-2sarge6
- from 0, < 0.99.2-1