Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-3140Wireshark vulnerability

7 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
5.9%
top 9.42%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 10
Latest updateMay 1

Description

The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.0.1-1 (bookworm)
Debianwireshark/wireshark< 1.0.1-1+3

🔴Vulnerability Details

2
GHSA
GHSA-fxxv-cmpr-cvx2: The syslog dissector in Wireshark (formerly Ethereal) 12022-05-01
OSV
CVE-2008-3140: The syslog dissector in Wireshark (formerly Ethereal) 12008-07-10

💥Exploits & PoCs

1
Exploit-DB
Wireshark 1.0.0 - Multiple Denial of Service Vulnerabilities2008-06-30

📋Vendor Advisories

2
Red Hat
wireshark: crash in the syslog dissector2008-06-30
Debian
CVE-2008-3140: wireshark - The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attack...2008

💬Community

1
Bugzilla
CVE-2008-3140 wireshark: crash in the syslog dissector2008-07-11