packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Feb 2, 2007 |
| Oracle_linux | — | Upgrade wiresharkUpgrade wireshark-gnome | Oct 16, 2024 | Feb 2, 2007 |
| Suse | — | Upgrade wireshark-develUpgrade libwireshark19Upgrade libwiretap15Upgrade wiresharkUpgrade wireshark-ui-qtUpgrade libwsutil17Upgrade libwiretap16Upgrade libwsutil16Upgrade libwireshark18 | Dec 12, 2013 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 0.99.5 | Oct 4, 2017 | Feb 2, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub