CVE-2008-4681: Input Validation
Published Oct 22, 2008
·Updated
Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.
Affected Software
12 affected components
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.6
Wireshark Wireshark=0.99.6a
Wireshark Wireshark=0.99.7
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0
Wireshark Wireshark=1.0.0
Wireshark Wireshark=1.0.1
Wireshark Wireshark=1.0.2
Remediation
Patch Available
Event History
Oct 22, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4681?
CVE-2008-4681 has been rated as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2008-4681?
To fix CVE-2008-4681, upgrade Wireshark to version 1.0.4 or later, which addresses this vulnerability.
3
Which versions of Wireshark are affected by CVE-2008-4681?
CVE-2008-4681 affects Wireshark versions 0.99.2 through 1.0.3.
4
What type of attack can exploit CVE-2008-4681?
CVE-2008-4681 can be exploited by sending specially crafted Bluetooth packets that cause Wireshark to crash.
5
Can CVE-2008-4681 be exploited remotely?
Yes, CVE-2008-4681 can be exploited remotely, leading to application crashes.