CVE-2008-3146: Buffer Overflow
Multiple buffer overflows in packetncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2008-3146?
CVE-2008-3146 is a vulnerability in Wireshark that involves multiple buffer overflows due to crafted NCP packets leading to potential application crashes and arbitrary code execution.
What software versions are affected by CVE-2008-3146?
CVE-2008-3146 affects Wireshark versions 0.9.7 through 1.0.2.
What is the risk associated with CVE-2008-3146?
The risk associated with CVE-2008-3146 includes denial of service attacks and the possibility of executing arbitrary code.
How do I fix CVE-2008-3146?
To fix CVE-2008-3146, you should upgrade to a later, patched version of Wireshark.
What symptoms indicate a CVE-2008-3146 exploitation attempt?
Symptoms of a CVE-2008-3146 exploitation attempt may include unexpected crashes or instability of Wireshark when processing NCP packets.