CVE-2007-0459: Medium severity Wireshark Wireshark vulnerability
Published Feb 2, 2007
·Updated
packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
Affected Software
3 affected components
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 2, 2007
CVE Published
08:28 PM
Feb 3, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0459?
CVE-2007-0459 has a severity level that can lead to denial of service, causing the application to crash or hang.
2
How do I fix CVE-2007-0459?
To resolve CVE-2007-0459, you should upgrade Wireshark to version 0.99.5 or later, which addresses this vulnerability.
3
Which versions of Wireshark are affected by CVE-2007-0459?
CVE-2007-0459 affects Wireshark versions 0.99.2 through 0.99.4.
4
What is the cause of the vulnerability CVE-2007-0459?
CVE-2007-0459 is caused by the TCP dissector in Wireshark mishandling fragmented HTTP packets.
5
Can CVE-2007-0459 be exploited remotely?
Yes, CVE-2007-0459 can be exploited remotely by attackers using specially crafted fragmented HTTP packets.