← Vulnerability feed

Vulnerability record · CVE-2004-0176 · published 4 May 2004

CVE-2004-0176: Ethereal dissector buffer overflows allow remote code execution

Ethereal Group · Ethereal

Ethereal versions 0.8.13 through 0.10.2 contain multiple buffer overflows in eight protocol dissectors: NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, and TCAP. A remote attacker can crash the analyzer or potentially execute arbitrary code by delivering crafted packets that trigger the affected dissector.

5.0 CVSS 2.0 Medium EPSS 67% · top 0.7%
5.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityAlthough the CVSS v2 score is medium, the flaw allows remote code execution without authentication and has a very high EPSS percentile, making it a serious risk for exposed or unpatched Ethereal deployments.

What it is

Ethereal versions 0.8.13 through 0.10.2 contain multiple buffer overflows in eight protocol dissectors: NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, and TCAP. A remote attacker can crash the analyzer or potentially execute arbitrary code by delivering crafted packets that trigger the affected dissector.

Impact

An attacker can cause a denial of service against the Ethereal process and may achieve arbitrary code execution in the context of the user running Ethereal. Because Ethereal is often run with elevated privileges for packet capture, successful exploitation could yield those privileges.

Attack surface

The flaw is reached over the network via malformed packets processed by the listed dissectors, with no authentication required per the CVSS vector AV:N/AC:L/Au:N. User interaction is required only insofar as a victim must capture or open traffic containing the crafted packets.

Exploitation

CVE-2004-0176 is not listed in CISA KEV and no ransomware associations are documented. EPSS estimates a 30-day exploitation probability of 0.67092 (99.266th percentile), indicating high predicted activity, but the record contains no confirmed in-the-wild exploitation reports.

What to do

  • Upgrade Ethereal to a version later than 0.10.2, or apply the vendor patches referenced in the Debian, Red Hat, Gentoo, and Mandriva advisories.
  • If immediate upgrade is not possible, disable or avoid the affected dissectors (NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, TCAP) where the tool permits.
  • Restrict capture of untrusted network traffic to trusted segments and avoid running Ethereal with unnecessary privileges.
  • Monitor vendor advisories for updated packages and apply distribution-specific security updates promptly.

Detection

  • Monitor for crashes or abnormal termination of the Ethereal process, especially when processing traffic on the affected protocols.
  • Inspect packet captures for malformed or unusually large NetFlow, IGAP, EIGRP, PGM, IrDA, BGP, ISUP, or TCAP packets.
  • Correlate Ethereal process failures with network traffic from untrusted sources to identify potential exploitation attempts.
  • Use host-based monitoring to detect unexpected child processes or code execution originating from the Ethereal process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
http://marc.info/?l=bugtraq&m=108007072215742&w=2
http://marc.info/?l=bugtraq&m=108058005324316&w=2
http://marc.info/?l=bugtraq&m=108213710306260&w=2
http://secunia.com/advisories/11185
http://security.e-matters.de/advisories/032004.html
http://security.gentoo.org/glsa/glsa-200403-07.xml
http://www.debian.org/security/2004/dsa-511 PatchVendor Advisory
http://www.ethereal.com/appnotes/enpa-sa-00013.html URL Repurposed
http://www.kb.cert.org/vuls/id/119876 US Government Resource
http://www.kb.cert.org/vuls/id/125156 US Government Resource
http://www.kb.cert.org/vuls/id/433596 US Government Resource
http://www.kb.cert.org/vuls/id/591820 US Government Resource
http://www.kb.cert.org/vuls/id/644886 US Government Resource
http://www.kb.cert.org/vuls/id/659140 US Government Resource
http://www.kb.cert.org/vuls/id/740188 US Government Resource
http://www.kb.cert.org/vuls/id/864884 US Government Resource
http://www.kb.cert.org/vuls/id/931588 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
http://www.osvdb.org/6893
http://www.redhat.com/support/errata/RHSA-2004-136.html
http://www.redhat.com/support/errata/RHSA-2004-137.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/15569
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10187
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A878
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A887
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000835
http://marc.info/?l=bugtraq&m=108007072215742&w=2
http://marc.info/?l=bugtraq&m=108058005324316&w=2
http://marc.info/?l=bugtraq&m=108213710306260&w=2
http://secunia.com/advisories/11185
http://security.e-matters.de/advisories/032004.html
http://security.gentoo.org/glsa/glsa-200403-07.xml
http://www.debian.org/security/2004/dsa-511 PatchVendor Advisory
http://www.ethereal.com/appnotes/enpa-sa-00013.html URL Repurposed
http://www.kb.cert.org/vuls/id/119876 US Government Resource
http://www.kb.cert.org/vuls/id/125156 US Government Resource
http://www.kb.cert.org/vuls/id/433596 US Government Resource
http://www.kb.cert.org/vuls/id/591820 US Government Resource
http://www.kb.cert.org/vuls/id/644886 US Government Resource

Track CVE-2004-0176 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-3628Ethereal group ethereal vulnerabilityMultiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly …EPSS 6.0%10.0CVE-2006-3632Ethereal group ethereal memory buffer overflow vulnerabilityBuffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code…EPSS 7.5%10.0CVE-2006-1932Ethereal group ethereal vulnerabilityOff-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.EPSS 2.6%10.0CVE-2005-3184Ethereal group ethereal vulnerabilityBuffer overflow vulnerability in the unicode_to_bytes in the Service Location Protocol (srvloc) dissector (packet-srvloc.c) in Ethereal allows remote…EPSS 7.6%10.0CVE-2004-0507Ethereal group ethereal vulnerabilityBuffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitra…EPSS 7.6%10.0CVE-2003-0431Ethereal group ethereal vulnerabilityThe tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.EPSS 2.3%10.0CVE-2003-0432Ethereal group ethereal vulnerabilityEthereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) IS…EPSS 2.3%7.8CVE-2007-6118Ethereal group ethereal vulnerabilityThe MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource c…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2004-0176), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.