32355Third-party advisory
http://secunia.com/advisories/32355 CVE-2008-4682
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
Record summary
CVE-2008-4682 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWireshark 1.0.x - '.ncf' Packet Capture Local Denial of ServiceExploitDB exploitby ShinnokNot analyzed1 file
References
Showing 12 of 2034144Third-party advisory
http://secunia.com/advisories/34144 4462Third-party advisory
http://securityreason.com/securityalert/4462 1021069vdb entry
http://securitytracker.com/id?1021069 shinnok.evonet.ro
http://shinnok.evonet.ro/vulns_html/wireshark.html support.avaya.comConfirmation
http://support.avaya.com/elmodocs2/security/ASA-2009-082.htm wiki.rpath.comConfirmation
http://wiki.rpath.com/Advisories:rPSA-2008-0336 MDVSA-2008:215Vendor advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:215 RHSA-2009:0313Vendor advisory
http://www.redhat.com/support/errata/RHSA-2009-0313.html 20081211 rPSA-2008-0336-1 tshark wiresharkmailing list
http://www.securityfocus.com/archive/1/499154/100/0/threaded 31468vdb entry
http://www.securityfocus.com/bid/31468 31838vdb entry
http://www.securityfocus.com/bid/31838