VDB
CVE-2008-3145
CVE-2008-3145
PUBLISHED
CVSS 5 MEDIUM
The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.
EPSS 2.00% · 80.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.00%
80.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wireshark | wireshark | 0.99.7, 0.8.19, 0.99.0 |
| n/a | n/a | n/a |
Timeline
- Jul 16, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
- Sep 13, 2023 EPSS Score
References
- SUSE-SR:2008:017 vendor-advisory
- http://www.wireshark.org/security/wnpa-sec-2008-04.html url
- 30181 vdb
- 20080729 rPSA-2008-0237-1 tshark wireshark mailing-list
- FEDORA-2008-6440 vendor-advisory
- oval:org.mitre.oval:def:9020 vdb
- https://issues.rpath.com/browse/RPL-2684 url
- 31687 third-party-advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0237 url
- GLSA-200808-04 vendor-advisory
- MDVSA-2008:152 vendor-advisory
- 31044 third-party-advisory
- ADV-2008-2773 vdb
- 32944 third-party-advisory
- DSA-1673 vendor-advisory
- https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2470 url
- RHSA-2008:0890 vendor-advisory
- ADV-2008-2057 vdb
- http://anonsvn.wireshark.org/viewvc/index.py?view=rev&revision=25343 url
- wireshark-packets-dos(43719) vdb
…and 8 more