CVE-2008-3934: Input Validation
Published Sep 4, 2008
·Updated
Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.
Affected Software
7 affected components
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0.1
Wireshark Wireshark=0.99.6
Wireshark Wireshark=1.0.2
Wireshark Wireshark=1.0.0
Wireshark Wireshark=0.99.6a
Wireshark Wireshark=0.99.7
Remediation
Patch Available
Event History
Sep 4, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3934?
CVE-2008-3934 has a severity rating indicating a denial of service vulnerability which can cause application crashes.
2
How do I fix CVE-2008-3934?
To fix CVE-2008-3934, update your Wireshark software to a version later than 1.0.2.
3
Which versions of Wireshark are affected by CVE-2008-3934?
Versions 0.99.6 through 1.0.2 of Wireshark are affected by CVE-2008-3934.
4
What types of attacks can exploit CVE-2008-3934?
CVE-2008-3934 can be exploited by attackers using crafted Tektronix .rf5 files to crash the application.
5
Is there a workaround for CVE-2008-3934?
The best workaround for CVE-2008-3934 is to avoid opening untrusted Tektronix .rf5 files until the software is updated.