CVE-2008-1070
published 2008-02-28CVE-2008-1070: The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.00%
78.7th percentile
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.8-1 (bookworm) | wireshark 0.99.8-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3948-x4f5-75xx: The SCTP dissector in Wireshark (formerly Ethereal) 0
ghsa_unreviewed·2022-05-01
CVE-2008-1070 [MEDIUM] GHSA-3948-x4f5-75xx: The SCTP dissector in Wireshark (formerly Ethereal) 0
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
OSV
CVE-2008-1070: The SCTP dissector in Wireshark (formerly Ethereal) 0
osv·2008-02-28·CVSS 5.0
CVE-2008-1070 [MEDIUM] CVE-2008-1070: The SCTP dissector in Wireshark (formerly Ethereal) 0
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Debian
CVE-2008-1070: wireshark - The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows...
vendor_debian·2008·CVSS 5.0
CVE-2008-1070 [MEDIUM] CVE-2008-1070: wireshark - The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows...
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Scope: local
bookworm: resolved (fixed in 0.99.8-1)
bullseye: resolved (fixed in 0.99.8-1)
forky: resolved (fixed in 0.99.8-1)
sid: resolved (fixed in 0.99.8-1)
trixie: resolved (fixed in 0.99.8-1)
Red Hat
wireshark: SCTP dissector crash
vendor_redhat·2007-02-27·CVSS 5.0
CVE-2008-1070 [MEDIUM] wireshark: SCTP dissector crash
wireshark: SCTP dissector crash
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/29156http://secunia.com/advisories/29188http://secunia.com/advisories/29223http://secunia.com/advisories/29242http://secunia.com/advisories/29511http://secunia.com/advisories/29736http://secunia.com/advisories/32091http://security.gentoo.org/glsa/glsa-200803-32.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-392.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0092http://www.mandriva.com/security/advisories?name=MDVSA-2008:057http://www.redhat.com/support/errata/RHSA-2008-0890.htmlhttp://www.securityfocus.com/archive/1/488967/100/0/threadedhttp://www.securityfocus.com/bid/28025http://www.securitytracker.com/id?1019515http://www.vupen.com/english/advisories/2008/0704http://www.vupen.com/english/advisories/2008/2773http://www.wireshark.org/security/wnpa-sec-2008-01.htmlhttps://issues.rpath.com/browse/RPL-2296https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11378https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14995https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00140.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00228.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/29156http://secunia.com/advisories/29188http://secunia.com/advisories/29223http://secunia.com/advisories/29242http://secunia.com/advisories/29511http://secunia.com/advisories/29736http://secunia.com/advisories/32091http://security.gentoo.org/glsa/glsa-200803-32.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-392.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0092http://www.mandriva.com/security/advisories?name=MDVSA-2008:057http://www.redhat.com/support/errata/RHSA-2008-0890.htmlhttp://www.securityfocus.com/archive/1/488967/100/0/threadedhttp://www.securityfocus.com/bid/28025http://www.securitytracker.com/id?1019515http://www.vupen.com/english/advisories/2008/0704http://www.vupen.com/english/advisories/2008/2773http://www.wireshark.org/security/wnpa-sec-2008-01.htmlhttps://issues.rpath.com/browse/RPL-2296https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11378https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14995https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00140.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00228.html
2008-02-28
Published