First published: Mon Mar 31 2008(Updated: )
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =0.99.8 | |
Wireshark Wireshark | =0.99.3 | |
Wireshark Wireshark | =0.99.6 | |
Wireshark Wireshark | =0.99.2 | |
Wireshark Wireshark | =0.99.5 | |
Wireshark Wireshark | =0.99.4 | |
Wireshark Wireshark | =0.99.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1562 is classified as a denial of service vulnerability that can cause the application to crash.
To mitigate CVE-2008-1562, upgrade Wireshark to the latest version that addresses the vulnerability.
CVE-2008-1562 affects Wireshark versions 0.99.2 through 0.99.8.
Yes, CVE-2008-1562 can be exploited remotely via malformed LDAP packets.
Running any version of Wireshark older than 0.99.8 puts your network at risk of remote denial of service attacks.