CVE-2008-1070: Medium severity wireshark vulnerability
Published Feb 28, 2008
·Updated
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Affected Software
15 affected components
Wireshark Wireshark=0.6
Wireshark Wireshark=0.7.9
Wireshark Wireshark=0.8.16
Wireshark Wireshark=0.9.10
Wireshark Wireshark=0.10
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.6
Wireshark Wireshark=0.99.7
Event History
Feb 28, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1070?
CVE-2008-1070 is classified as a low severity vulnerability because it allows remote attackers to cause a denial of service (crash) in specific versions of Wireshark.
2
How do I fix CVE-2008-1070?
To address CVE-2008-1070, upgrade to a patched version of Wireshark that is not affected by this vulnerability.
3
Which versions of Wireshark are affected by CVE-2008-1070?
CVE-2008-1070 affects Wireshark versions 0.99.5 to 0.99.7 and several earlier versions.
4
What type of vulnerability is CVE-2008-1070?
CVE-2008-1070 is a denial of service vulnerability caused by malformed SCTP packets.
5
Can CVE-2008-1070 be exploited remotely?
Yes, CVE-2008-1070 can be exploited remotely through the delivery of crafted SCTP packets.