CVE-2008-4680: Medium severity wireshark vulnerability
Published Oct 22, 2008
·Updated
packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).
Affected Software
7 affected components
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0.1
Wireshark Wireshark=1.0
Wireshark Wireshark=1.0.2
Wireshark Wireshark=1.0.3
Wireshark Wireshark=1.0.0
Wireshark Wireshark=0.99.7
Remediation
Patch Available
Event History
Oct 22, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4680?
CVE-2008-4680 has a severity rating that indicates it can lead to a denial of service through a crash or abort of the application.
2
How do I fix CVE-2008-4680?
To fix CVE-2008-4680, you should upgrade to Wireshark version 1.0.4 or later.
3
Which versions of Wireshark are affected by CVE-2008-4680?
CVE-2008-4680 affects Wireshark versions 0.99.7 through 1.0.3.
4
What kind of attack is described in CVE-2008-4680?
CVE-2008-4680 describes a remote attack that can result in a denial of service through a malformed USB Request Block.
5
Can CVE-2008-4680 be exploited remotely?
Yes, CVE-2008-4680 can be exploited remotely by sending a specially crafted USB Request Block.