CVE Vulnerabilities

CVE-2008-4684

Published: Oct 22, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

packet-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle exceptions thrown by post dissectors, which allows remote attackers to cause a denial of service (application crash) via a certain series of packets, as demonstrated by enabling the (1) PRP or (2) MATE post dissector.

Affected Software

NameVendorStart VersionEnd Version
WiresharkWireshark0.99.2 (including)0.99.2 (including)
WiresharkWireshark0.99.3 (including)0.99.3 (including)
WiresharkWireshark0.99.4 (including)0.99.4 (including)
WiresharkWireshark0.99.5 (including)0.99.5 (including)
WiresharkWireshark0.99.6 (including)0.99.6 (including)
WiresharkWireshark0.99.6a (including)0.99.6a (including)
WiresharkWireshark0.99.7 (including)0.99.7 (including)
WiresharkWireshark0.99.8 (including)0.99.8 (including)
WiresharkWireshark1.0 (including)1.0 (including)
WiresharkWireshark1.0.0 (including)1.0.0 (including)
WiresharkWireshark1.0.1 (including)1.0.1 (including)
WiresharkWireshark1.0.2 (including)1.0.2 (including)
WiresharkWireshark1.0.3 (including)1.0.3 (including)
Red Hat Enterprise Linux 3RedHatwireshark-0:1.0.6-EL3.3*
Red Hat Enterprise Linux 4RedHatwireshark-0:1.0.6-2.el4_7*
Red Hat Enterprise Linux 5RedHatwireshark-0:1.0.6-2.el5_3*
WiresharkUbuntugutsy*
WiresharkUbuntuhardy*
WiresharkUbuntuintrepid*
WiresharkUbuntuupstream*

References