CVE-2008-4685: Use After Free
Use-after-free vulnerability in the dissectq931causeie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via certain packets that trigger an exception.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4685?
CVE-2008-4685 has a severity rating that indicates it could lead to a denial of service through application crashes.
How do I fix CVE-2008-4685?
To fix CVE-2008-4685, update your Wireshark installation to a version later than 1.0.3 that addresses this vulnerability.
Which versions of Wireshark are affected by CVE-2008-4685?
CVE-2008-4685 affects Wireshark versions from 0.10.3 to 1.0.3, including several intermediary releases.
Can CVE-2008-4685 be exploited remotely?
Yes, CVE-2008-4685 can be exploited remotely by sending specially crafted packets to trigger the vulnerability.
What are the potential impacts of CVE-2008-4685?
The potential impact of CVE-2008-4685 includes application crashes, leading to a denial of service for users running vulnerable versions of Wireshark.