Wireshark Multiple Protocol Denial of Service Vulnerabilities
BID:24662
Info
Wireshark Multiple Protocol Denial of Service Vulnerabilities
| Bugtraq ID: | 24662 |
| Class: | Unknown |
| CVE: |
CVE-2007-3389 CVE-2007-3390 CVE-2007-3391 CVE-2007-3392 CVE-2007-3393 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Mar 19 2015 09:01AM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Wireshark Wireshark 0.99.5 Wireshark Wireshark 0.99.4 Wireshark Wireshark 0.99.3 Wireshark Wireshark 0.99.2 Wireshark Wireshark 0.99.1 Wireshark Wireshark 0.99 Wireshark Wireshark 0.9.10 Wireshark Wireshark 0.8.16 Wireshark Wireshark 0.7.9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Office Server S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc S.u.S.E. Linux 10.0 x86-64 S.u.S.E. Linux 10.0 x86 S.u.S.E. Linux 10.0 ppc rPath rPath Linux 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Desktop 4.0 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha |
| Not Vulnerable: |
Wireshark Wireshark 0.99.6 |
Discussion
Wireshark Multiple Protocol Denial of Service Vulnerabilities
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may permit attackers to cause crashes and deny service to legitimate users of the application.
Versions prior to Wireshark 0.99.6 are affected.
Wireshark is prone to multiple denial-of-service vulnerabilities.
Exploiting these issues may permit attackers to cause crashes and deny service to legitimate users of the application.
Versions prior to Wireshark 0.99.6 are affected.
Exploit / POC
Wireshark Multiple Protocol Denial of Service Vulnerabilities
The following exploits are available:
The following exploits are available:
Solution / Fix
Wireshark Multiple Protocol Denial of Service Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Wireshark Multiple Protocol Denial of Service Vulnerabilities
References:
References:
- Wireshark 0.99.6 Release Notes (Wireshark)
- Wireshark DNP3 Dissector Bug Lets Remote Users Deny Service (SecuriTeam)
- Wireshark Homepage (Wireshark)
- Wireshark DNP3 Dissector Infinite Loop Vulnerability ([email protected])
- WireShark MMS Remote Denial of Service vulnerability (zwell)
- RHSA-2007:0709 Low: wireshark security and bug fix update (Red Hat)
- RHSA-2007:0710-2 wireshark security update (Red Hat)
- RHSA-2008:0059-6 Moderate: wireshark security update (Red Hat)
- Wireshark DNP3 Dissector Infinite Loop Vulnerability (SecuriTeam)