CVE-2007-6121: Input Validation
Published Nov 23, 2007
·Updated
Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.
Affected Software
53 affected components
Ethereal Group Ethereal=0.8.16
Ethereal Group Ethereal=0.8.17
Ethereal Group Ethereal=0.8.17a
Ethereal Group Ethereal=0.8.18
Ethereal Group Ethereal=0.8.19
Ethereal Group Ethereal=0.8.20
Ethereal Group Ethereal=0.9
Ethereal Group Ethereal=0.9.0
Ethereal Group Ethereal=0.9.1
Ethereal Group Ethereal=0.9.2
Ethereal Group Ethereal=0.9.3
Ethereal Group Ethereal=0.9.4
Ethereal Group Ethereal=0.9.5
Ethereal Group Ethereal=0.9.6
Ethereal Group Ethereal=0.9.7
Ethereal Group Ethereal=0.9.8
Ethereal Group Ethereal=0.9.9
Ethereal Group Ethereal=0.9.10
Ethereal Group Ethereal=0.9.11
Ethereal Group Ethereal=0.9.12
Ethereal Group Ethereal=0.9.13
Ethereal Group Ethereal=0.9.14
Ethereal Group Ethereal=0.9.15
Ethereal Group Ethereal=0.9.16
Ethereal Group Ethereal=0.10
Ethereal Group Ethereal=0.10.0
Ethereal Group Ethereal=0.10.0a
Ethereal Group Ethereal=0.10.1
Ethereal Group Ethereal=0.10.2
Ethereal Group Ethereal=0.10.3
Ethereal Group Ethereal=0.10.4
Ethereal Group Ethereal=0.10.5
Ethereal Group Ethereal=0.10.6
Ethereal Group Ethereal=0.10.7
Ethereal Group Ethereal=0.10.8
Ethereal Group Ethereal=0.10.9
Ethereal Group Ethereal=0.10.10
Ethereal Group Ethereal=0.10.11
Ethereal Group Ethereal=0.10.12
Ethereal Group Ethereal=0.10.13
Ethereal Group Ethereal=0.10.14
Ethereal Group Ethereal=0.99.0
Wireshark Wireshark=0.8.16
Wireshark Wireshark=0.9.8
Wireshark Wireshark=0.9.10
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.0
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.6
Remediation
Patch Available
Patch Available
Event History
Nov 23, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6121?
CVE-2007-6121 is classified as a denial of service vulnerability affecting specific versions of Wireshark and Ethereal.
2
How do I fix CVE-2007-6121?
To remediate CVE-2007-6121, upgrade to a version of Wireshark or Ethereal that is not vulnerable to this issue.
3
What versions of software are affected by CVE-2007-6121?
CVE-2007-6121 affects Wireshark versions from 0.8.16 to 0.99.6 and various versions of Ethereal from 0.8.16 to 0.10.14.
4
Can CVE-2007-6121 be exploited remotely?
Yes, CVE-2007-6121 can be exploited by remote attackers sending malformed RPC Portmap packets.
5
What is the impact of CVE-2007-6121?
The impact of CVE-2007-6121 is that it can cause the Wireshark or Ethereal application to crash, resulting in a denial of service.