Back

CVE-2005-2367

Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.

Published: Aug 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (25)

Vendor Product Version
ethereal_group ethereal 0.9.4
ethereal_group ethereal 0.9.5
ethereal_group ethereal 0.9.6
ethereal_group ethereal 0.9.7
ethereal_group ethereal 0.9.8
ethereal_group ethereal 0.9.9
ethereal_group ethereal 0.9.10
ethereal_group ethereal 0.9.11
ethereal_group ethereal 0.9.12
ethereal_group ethereal 0.9.13
ethereal_group ethereal 0.9.14
ethereal_group ethereal 0.9.15
ethereal_group ethereal 0.9.16
ethereal_group ethereal 0.10.0
ethereal_group ethereal 0.10.1
ethereal_group ethereal 0.10.2
ethereal_group ethereal 0.10.3
ethereal_group ethereal 0.10.4
ethereal_group ethereal 0.10.5
ethereal_group ethereal 0.10.6

…and 5 more

GitHub Security Advisory GHSA-jq42-836h-c5wg

Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 6.14%

Top 7% most likely to be exploited

Threat Score 31.8 / 100

Data Sources

NVD EPSS GitHub