CVE-2007-3390: Medium severity Wireshark Wireshark vulnerability
Published Jun 26, 2007
·Updated
Wireshark 0.99.5 and 0.10.x up to 0.10.14, when running on certain systems, allows remote attackers to cause a denial of service (crash) via crafted iSeries capture files that trigger a SIGTRAP.
Affected Software
16 affected components
Wireshark Wireshark=0.10.3
Wireshark Wireshark=0.10.6
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.10
Wireshark Wireshark=0.10.14
Wireshark Wireshark=0.10.1
Wireshark Wireshark=0.10.9
Wireshark Wireshark=0.10.7
Wireshark Wireshark=0.10.8
Wireshark Wireshark=0.10.2
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.10.12
Wireshark Wireshark=0.10.10
Wireshark Wireshark=0.10.5
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.10.11
Remediation
Patch Available
Event History
Jun 26, 2007
CVE Published
12:30 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3390?
CVE-2007-3390 is classified as a denial of service vulnerability, allowing attackers to cause crashes in vulnerable versions of Wireshark.
2
How do I fix CVE-2007-3390?
To fix CVE-2007-3390, upgrade to a Wireshark version that is beyond 0.10.14, as the vulnerability is patched in these later releases.
3
What versions of Wireshark are affected by CVE-2007-3390?
CVE-2007-3390 affects Wireshark versions 0.99.5 and 0.10.x up to 0.10.14.
4
Can CVE-2007-3390 be exploited remotely?
Yes, CVE-2007-3390 can be exploited remotely through crafted iSeries capture files.
5
What is the impact of CVE-2007-3390?
The impact of CVE-2007-3390 is a denial of service, specifically causing the application to crash.