CVE-2008-1072: Medium severity wireshark vulnerability
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1072?
CVE-2008-1072 is considered a high severity vulnerability as it allows remote attackers to cause denial of service through malformed packets.
How do I fix CVE-2008-1072?
To fix CVE-2008-1072, update Wireshark to a version later than 0.99.7 that addresses this vulnerability.
Which versions of Wireshark are affected by CVE-2008-1072?
CVE-2008-1072 affects multiple versions of Wireshark including 0.6.0 to 0.99.7, with specific notable versions such as 0.9.10 and 0.99.7.
What types of attacks can exploit CVE-2008-1072?
CVE-2008-1072 can be exploited through denial of service attacks by sending specially crafted TFTP packets.
Is CVE-2008-1072 present in any Linux distributions?
Yes, CVE-2008-1072 is noted to affect versions of Wireshark running on Ubuntu 7.10.