CVE-2008-3145: Input Validation
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-3145 to the following vulnerability:
An unspecified flaw packet reassemblin in Wireshark (formerly Ethereal) 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via unknown vectors.
References: http://www.wireshark.org/security/wnpa-sec-2008-04.html
Upstream bug: https://bugs.wireshark.org/bugzilla/showbug.cgi?id=2470
Upstream commit: http://anonsvn.wireshark.org/viewvc/index.py?view=rev&revision=25343
Other sources
The fragmentaddwork function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3145?
CVE-2008-3145 is classified as a denial of service vulnerability that can cause applications to crash.
How do I fix CVE-2008-3145?
To fix CVE-2008-3145, upgrade Wireshark to version 1.0.3 or later.
Which versions of Wireshark are affected by CVE-2008-3145?
CVE-2008-3145 affects Wireshark versions 0.8.19 through 1.0.1.
What type of attack does CVE-2008-3145 involve?
CVE-2008-3145 involves sending fragmented packets with non-sequential fragmentation offsets.
Can CVE-2008-3145 be exploited remotely?
Yes, CVE-2008-3145 can be exploited remotely by sending specially crafted packets.