Vulnerability record · CVE-2004-0176 · published 4 May 2004
CVE-2004-0176: Ethereal dissector buffer overflows allow remote code execution
Ethereal Group · Ethereal
Ethereal versions 0.8.13 through 0.10.2 contain multiple buffer overflows in eight protocol dissectors: NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, and TCAP. A remote attacker can crash the analyzer or potentially execute arbitrary code by delivering crafted packets that trigger the affected dissector.
Description
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityAlthough the CVSS v2 score is medium, the flaw allows remote code execution without authentication and has a very high EPSS percentile, making it a serious risk for exposed or unpatched Ethereal deployments.
What it is
Ethereal versions 0.8.13 through 0.10.2 contain multiple buffer overflows in eight protocol dissectors: NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, and TCAP. A remote attacker can crash the analyzer or potentially execute arbitrary code by delivering crafted packets that trigger the affected dissector.
Impact
An attacker can cause a denial of service against the Ethereal process and may achieve arbitrary code execution in the context of the user running Ethereal. Because Ethereal is often run with elevated privileges for packet capture, successful exploitation could yield those privileges.
Attack surface
The flaw is reached over the network via malformed packets processed by the listed dissectors, with no authentication required per the CVSS vector AV:N/AC:L/Au:N. User interaction is required only insofar as a victim must capture or open traffic containing the crafted packets.
Exploitation
CVE-2004-0176 is not listed in CISA KEV and no ransomware associations are documented. EPSS estimates a 30-day exploitation probability of 0.67092 (99.266th percentile), indicating high predicted activity, but the record contains no confirmed in-the-wild exploitation reports.
What to do
- Upgrade Ethereal to a version later than 0.10.2, or apply the vendor patches referenced in the Debian, Red Hat, Gentoo, and Mandriva advisories.
- If immediate upgrade is not possible, disable or avoid the affected dissectors (NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, TCAP) where the tool permits.
- Restrict capture of untrusted network traffic to trusted segments and avoid running Ethereal with unnecessary privileges.
- Monitor vendor advisories for updated packages and apply distribution-specific security updates promptly.
Detection
- Monitor for crashes or abnormal termination of the Ethereal process, especially when processing traffic on the affected protocols.
- Inspect packet captures for malformed or unusually large NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, or TCAP packets.
- Correlate Ethereal process failures with network traffic from untrusted sources to identify potential exploitation attempts.
- Use host-based monitoring to detect unexpected child processes or code execution originating from the Ethereal process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0176 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.