PT-2008-5263 · Wireshark+1 · Wireshark+1

Published

2008-09-04

·

Updated

2018-10-11

·

CVE-2008-3933

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 0.10.14 through 1.0.2
Description The issue allows attackers to cause a denial of service, resulting in a crash, by sending a packet with crafted zlib-compressed data. This triggers an invalid read in the tvb uncompress function.
Recommendations For versions 0.10.14 through 1.0.2, consider disabling the tvb uncompress function as a temporary workaround until a patch is available. Restrict access to untrusted packets to minimize the risk of exploitation.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3933
DSA-1673-1
DTSA-167-1
RHSA-2008:0890
RHSA-2008_0890

Affected Products

Red Hat
Wireshark