CVE-2007-0456
published 2007-02-02CVE-2007-0456: Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.70%
74.9th percentile
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.4-5 (bookworm) | wireshark 0.99.4-5 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
vendor_redhat·2007-02-01·CVSS 4.3
CVE-2007-0456 [MEDIUM] Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Debian
CVE-2007-0456: wireshark - Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) ...
vendor_debian·2007·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456: wireshark - Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) ...
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.99.4-5)
bullseye: resolved (fixed in 0.99.4-5)
forky: resolved (fixed in 0.99.4-5)
sid: resolved (fixed in 0.99.4-5)
trixie: resolved (fixed in 0.99.4-5)
GHSA
GHSA-gf86-2rm8-p798: Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0
ghsa_unreviewed·2022-05-03
CVE-2007-0456 [MEDIUM] GHSA-gf86-2rm8-p798: Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
OSV
CVE-2007-0456: Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0
osv·2007-02-02·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456: Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-02-02·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
+++ This bug was initially created as a clone of Bug #225689 +++
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-01-31·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
+++ This bug was initially created as a clone of Bug #225689 +++
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-01-31·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
Discussion:
These flaws also affect RHEL2.1 and RHEL3
---
ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://fedoranews.org/cms/node/2565http://osvdb.org/33073http://secunia.com/advisories/24011http://secunia.com/advisories/24016http://secunia.com/advisories/24025http://secunia.com/advisories/24084http://secunia.com/advisories/24515http://secunia.com/advisories/24650http://secunia.com/advisories/24970http://securitytracker.com/id?1017581http://support.avaya.com/elmodocs2/security/ASA-2007-166.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:033http://www.redhat.com/support/errata/RHSA-2007-0066.htmlhttp://www.securityfocus.com/bid/22352http://www.vupen.com/english/advisories/2007/0443http://www.wireshark.org/security/wnpa-sec-2007-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/32056https://issues.rpath.com/browse/RPL-985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11342https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14867ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://fedoranews.org/cms/node/2565http://osvdb.org/33073http://secunia.com/advisories/24011http://secunia.com/advisories/24016http://secunia.com/advisories/24025http://secunia.com/advisories/24084http://secunia.com/advisories/24515http://secunia.com/advisories/24650http://secunia.com/advisories/24970http://securitytracker.com/id?1017581http://support.avaya.com/elmodocs2/security/ASA-2007-166.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:033http://www.redhat.com/support/errata/RHSA-2007-0066.htmlhttp://www.securityfocus.com/bid/22352http://www.vupen.com/english/advisories/2007/0443http://www.wireshark.org/security/wnpa-sec-2007-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/32056https://issues.rpath.com/browse/RPL-985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11342https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14867
2007-02-02
Published