CVE-2008-1072
MEDIUM severity · CVSS 4.7
4.7CVSS MEDIUM
Summary
The TFTP dissector in Wireshark (formerly Ethereal) 0.6.0 through 0.99.7, when running on Ubuntu 7.10, allows remote attackers to cause a denial of service (crash or memory consumption) via a malformed packet, possibly related to a Cairo library bug.
Impact & exploitability
Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)1%
AV:L/AC:M/Au:N/C:N/I:N/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://secunia.com/advisories/29156Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://secunia.com/advisories/29188
- http://secunia.com/advisories/29223
- http://secunia.com/advisories/29242
- http://secunia.com/advisories/29511
- http://secunia.com/advisories/29736
- http://secunia.com/advisories/32091