CVE-2008-3137Improper Input Validation in Wireshark

Severity
4.3MEDIUMNVD
EPSS
2.9%
top 13.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Latest updateMay 1

Description

The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.0.1-1 (bookworm)
Debianwireshark/wireshark< 1.0.1-1+3
NVDwireshark/wireshark10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8mv6-3mvr-36hm: The GSM SMS dissector in Wireshark (formerly Ethereal) 02022-05-01
OSV
CVE-2008-3137: The GSM SMS dissector in Wireshark (formerly Ethereal) 02008-07-10

📋Vendor Advisories

2
Red Hat
wireshark: crash in the GSM SMS dissector2008-06-30
Debian
CVE-2008-3137: wireshark - The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allo...2008

💬Community

1
Bugzilla
CVE-2008-3137 wireshark: crash in the GSM SMS dissector2008-07-11