CVE-2008-1072
published 2008-02-28CVE-2008-1072: The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.72%
50.0th percentile
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 0.99.8-1 (bookworm) | wireshark 0.99.8-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
| wireshark | wireshark | >= 0 < 0.99.8-1 | 0.99.8-1 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2008-1072: wireshark - The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when r...
vendor_debian·2008·CVSS 4.7
CVE-2008-1072 [MEDIUM] CVE-2008-1072: wireshark - The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when r...
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
Scope: local
bookworm: resolved (fixed in 0.99.8-1)
bullseye: resolved (fixed in 0.99.8-1)
forky: resolved (fixed in 0.99.8-1)
sid: resolved (fixed in 0.99.8-1)
trixie: resolved (fixed in 0.99.8-1)
Red Hat
wireshark: TFTP dissector crash
vendor_redhat·2007-02-27·CVSS 4.7
CVE-2008-1072 [MEDIUM] wireshark: TFTP dissector crash
wireshark: TFTP dissector crash
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
GHSA
GHSA-whmj-wvpf-4c6j: The TFTP dissector in Wireshark (formerly Ethereal) 0
ghsa_unreviewed·2022-05-01
CVE-2008-1072 [MEDIUM] GHSA-whmj-wvpf-4c6j: The TFTP dissector in Wireshark (formerly Ethereal) 0
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
OSV
CVE-2008-1072: The TFTP dissector in Wireshark (formerly Ethereal) 0
osv·2008-02-28·CVSS 4.7
CVE-2008-1072 [MEDIUM] CVE-2008-1072: The TFTP dissector in Wireshark (formerly Ethereal) 0
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/29156http://secunia.com/advisories/29188http://secunia.com/advisories/29223http://secunia.com/advisories/29242http://secunia.com/advisories/29511http://secunia.com/advisories/29736http://secunia.com/advisories/32091http://security.gentoo.org/glsa/glsa-200803-32.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-392.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0092http://www.mandriva.com/security/advisories?name=MDVSA-2008:057http://www.redhat.com/support/errata/RHSA-2008-0890.htmlhttp://www.securityfocus.com/archive/1/488967/100/0/threadedhttp://www.securityfocus.com/bid/28025http://www.securitytracker.com/id?1019515http://www.vupen.com/english/advisories/2008/0704http://www.vupen.com/english/advisories/2008/2773http://www.wireshark.org/security/wnpa-sec-2008-01.htmlhttps://issues.rpath.com/browse/RPL-2296https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10188https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00140.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00228.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/29156http://secunia.com/advisories/29188http://secunia.com/advisories/29223http://secunia.com/advisories/29242http://secunia.com/advisories/29511http://secunia.com/advisories/29736http://secunia.com/advisories/32091http://security.gentoo.org/glsa/glsa-200803-32.xmlhttp://support.avaya.com/elmodocs2/security/ASA-2008-392.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0092http://www.mandriva.com/security/advisories?name=MDVSA-2008:057http://www.redhat.com/support/errata/RHSA-2008-0890.htmlhttp://www.securityfocus.com/archive/1/488967/100/0/threadedhttp://www.securityfocus.com/bid/28025http://www.securitytracker.com/id?1019515http://www.vupen.com/english/advisories/2008/0704http://www.vupen.com/english/advisories/2008/2773http://www.wireshark.org/security/wnpa-sec-2008-01.htmlhttps://issues.rpath.com/browse/RPL-2296https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10188https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00140.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00228.html
2008-02-28
Published