CVE-2008-1071: Medium severity wireshark vulnerability
Published Feb 28, 2008
·Updated
The SNMP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.7 allows remote attackers to cause a denial of service (crash) via a malformed packet.
Affected Software
15 affected components
Wireshark Wireshark=0.9.10
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.8.16
Wireshark Wireshark=0.10
Wireshark Wireshark=0.99.6
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.7.9
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.7
Wireshark Wireshark=0.6
Event History
Feb 28, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1071?
CVE-2008-1071 has been classified as a high severity vulnerability due to its ability to cause a denial of service.
2
How do I fix CVE-2008-1071?
To fix CVE-2008-1071, update your Wireshark to a version later than 0.99.7.
3
What versions of Wireshark are affected by CVE-2008-1071?
CVE-2008-1071 affects Wireshark versions 0.99.6 through 0.99.7 and earlier versions.
4
Can CVE-2008-1071 be exploited remotely?
Yes, CVE-2008-1071 can be exploited remotely through malformed SNMP packets.
5
What are the implications of CVE-2008-1071 for users?
Users of the affected versions of Wireshark could experience crashes leading to potential denial of service during network analysis.