CVE-2008-1072Wireshark vulnerability

6 documents6 sources
Severity
4.7MEDIUMNVD
EPSS
0.1%
top 70.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28
Latest updateMay 1

Description

The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 0.99.8-1 (bookworm)
Debianwireshark/wireshark< 0.99.8-1+3
NVDwireshark/wireshark15 versions+14

🔴Vulnerability Details

2
GHSA
GHSA-whmj-wvpf-4c6j: The TFTP dissector in Wireshark (formerly Ethereal) 02022-05-01
OSV
CVE-2008-1072: The TFTP dissector in Wireshark (formerly Ethereal) 02008-02-28

📋Vendor Advisories

2
Debian
CVE-2008-1072: wireshark - The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when r...2008
Red Hat
wireshark: TFTP dissector crash2007-02-27

💬Community

1
Bugzilla
CVE-2008-1072 wireshark: TFTP dissector crash2008-02-29