packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wireshark | Wireshark | 0.99.2 (including) | 0.99.2 (including) |
| Wireshark | Wireshark | 0.99.3 (including) | 0.99.3 (including) |
| Wireshark | Wireshark | 0.99.4 (including) | 0.99.4 (including) |
| Red Hat Enterprise Linux 2.1 | RedHat | wireshark-0:0.99.5-AS21.3 | * |
| Red Hat Enterprise Linux 3 | RedHat | wireshark-0:0.99.5-EL3.1 | * |
| Red Hat Enterprise Linux 4 | RedHat | wireshark-0:0.99.5-EL4.1 | * |
| Red Hat Enterprise Linux 5 | RedHat | wireshark-0:0.99.5-1.el5 | * |
| Ethereal | Ubuntu | dapper | * |
| Wireshark | Ubuntu | edgy | * |
| Wireshark | Ubuntu | upstream | * |