CVE-2007-6118: High severity Wireshark Wireshark vulnerability
Published Nov 23, 2007
·Updated
The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.
Affected Software
12 affected components
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.0
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.99.0
Ethereal Group Ethereal=0.9.16
Wireshark Wireshark=0.99.6
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99
Remediation
Patch Available
Patch Available
Event History
Nov 23, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6118?
CVE-2007-6118 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-6118?
To fix CVE-2007-6118, upgrade Wireshark or Ethereal to a version that is not affected, specifically version 0.99.7 or later.
3
What software is affected by CVE-2007-6118?
CVE-2007-6118 affects Wireshark versions 0.9.14 to 0.99.6 and Ethereal versions 0.9.14 to 0.9.16.
4
What type of attack is associated with CVE-2007-6118?
CVE-2007-6118 allows remote attackers to perform a denial of service attack which leads to resource consumption and infinite loops.
5
When was CVE-2007-6118 disclosed?
CVE-2007-6118 was disclosed in 2007.