CVE-2008-5285: Medium severity wireshark vulnerability
A security flaw was found in the Wireshark's SMTP dissector -- routines for SMTP packet disassembly. A remote attacker could use this flaw to cause a denial of service (infinite loop) via sending a large SMTP request to port 25.
References: http://packetstormsecurity.org/0811-advisories/wireshark104-dos.txt http://www.securityfocus.com/archive/1/498562/30/0/threaded http://www.nabble.com/-SVRT-04-08--Vulnerability-in-WireShark-1.0.4-for-DoS-Attack-td20640164.html
Proposed upstream patches: http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-smtp.c?r1=24989&r2=24988&pathrev=24989&view=patch http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-smtp.c?r1=24994&r2=24993&pathrev=24994&view=patch
Other sources
Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5285?
CVE-2008-5285 has a moderate severity level as it can cause a denial of service through an infinite loop.
How do I fix CVE-2008-5285?
To fix CVE-2008-5285, it is recommended to upgrade to a patched version of Wireshark that addresses this vulnerability.
Which versions of Wireshark are affected by CVE-2008-5285?
CVE-2008-5285 affects multiple older versions of Wireshark, including 0.8.16 to 1.0.4.
What kind of attack could exploit CVE-2008-5285?
An attacker could exploit CVE-2008-5285 by sending a large SMTP request to port 25, resulting in a denial of service.
Is CVE-2008-5285 still a concern for current Wireshark users?
CVE-2008-5285 is primarily a concern for users running outdated versions of Wireshark that have not been updated.