CVE-2007-0459
published 2007-02-02CVE-2007-0459: packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.10%
79.8th percentile
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.4-5 (bookworm) | wireshark 0.99.4-5 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
| wireshark | wireshark | >= 0 < 0.99.4-5 | 0.99.4-5 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qvq9-f42r-93qf: packet-tcp
ghsa_unreviewed·2022-05-03
CVE-2007-0459 [MEDIUM] GHSA-qvq9-f42r-93qf: packet-tcp
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
OSV
CVE-2007-0459: packet-tcp
osv·2007-02-02·CVSS 5.0
CVE-2007-0459 [MEDIUM] CVE-2007-0459: packet-tcp
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
Red Hat
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
vendor_redhat·2007-02-01·CVSS 5.0
CVE-2007-0458 [MEDIUM] Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.
Red Hat
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
vendor_redhat·2007-02-01·CVSS 4.3
CVE-2007-0459 [MEDIUM] Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
Red Hat
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
vendor_redhat·2007-02-01·CVSS 4.3
CVE-2007-0456 [MEDIUM] Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Red Hat
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
vendor_redhat·2007-02-01·CVSS 4.3
CVE-2007-0457 [MEDIUM] Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
Debian
CVE-2007-0459: wireshark - packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 throug...
vendor_debian·2007·CVSS 5.0
CVE-2007-0459 [MEDIUM] CVE-2007-0459: wireshark - packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 throug...
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
Scope: local
bookworm: resolved (fixed in 0.99.4-5)
bullseye: resolved (fixed in 0.99.4-5)
forky: resolved (fixed in 0.99.4-5)
sid: resolved (fixed in 0.99.4-5)
trixie: resolved (fixed in 0.99.4-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-02-02·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
+++ This bug was initially created as a clone of Bug #225689 +++
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-01-31·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
+++ This bug was initially created as a clone of Bug #225689 +++
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0
Bugzilla
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
bugzilla·2007-01-31·CVSS 4.3
CVE-2007-0456 [MEDIUM] CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
CVE-2007-0456 Multiple Wireshark issues (CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)
Wireshark 0.99.5 is set to be released in a few days, it fixes four flaws, all
of which will only result in a crash:
CVE-2007-0459
The TCP dissector could hang or crash while reassembling HTTP packets.
Fixed in: r19859
Bug IDs: 1200
Versions affected: 0.99.2 to 0.99.4
CVE-2007-0459
The HTTP dissector could crash.
Fixed in: r19899
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
CVE-2007-0457
On some systems, the IEEE 802.11 dissector could crash.
Fixed in: r20126
Bug IDs: None
Versions affected: 0.10.14 to 0.99.4
CVE-2007-0456
On some systems, the LLT dissector could crash.
Fixed in: r20007
Bug IDs: None
Versions affected: 0.99.3 to 0.99.4
Discussion:
These flaws also affect RHEL2.1 and RHEL3
---
ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200http://fedoranews.org/cms/node/2565http://secunia.com/advisories/24011http://secunia.com/advisories/24016http://secunia.com/advisories/24025http://secunia.com/advisories/24084http://secunia.com/advisories/24515http://secunia.com/advisories/24650http://secunia.com/advisories/24970http://securitytracker.com/id?1017581http://support.avaya.com/elmodocs2/security/ASA-2007-166.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:033http://www.redhat.com/support/errata/RHSA-2007-0066.htmlhttp://www.securityfocus.com/bid/22352http://www.vupen.com/english/advisories/2007/0443http://www.wireshark.org/security/wnpa-sec-2007-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/32053https://issues.rpath.com/browse/RPL-985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10465https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14875ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1200http://fedoranews.org/cms/node/2565http://secunia.com/advisories/24011http://secunia.com/advisories/24016http://secunia.com/advisories/24025http://secunia.com/advisories/24084http://secunia.com/advisories/24515http://secunia.com/advisories/24650http://secunia.com/advisories/24970http://securitytracker.com/id?1017581http://support.avaya.com/elmodocs2/security/ASA-2007-166.htmhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:033http://www.redhat.com/support/errata/RHSA-2007-0066.htmlhttp://www.securityfocus.com/bid/22352http://www.vupen.com/english/advisories/2007/0443http://www.wireshark.org/security/wnpa-sec-2007-01.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/32053https://issues.rpath.com/browse/RPL-985https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10465https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14875
2007-02-02
Published