PublicDate: 2008-07-16 18:41:00 UTC Candidate: CVE-2008-3145 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3145 Description: The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_wireshark: upstream_wireshark: released (1.0.2) dapper_wireshark: DNE feisty_wireshark: needs-triage (reached end-of-life) gutsy_wireshark: needs-triage (reached end-of-life) hardy_wireshark: ignored (reached end-of-life) intrepid_wireshark: not-affected (1.0.3-1ubuntu2.2) jaunty_wireshark: not-affected karmic_wireshark: not-affected lucid_wireshark: not-affected maverick_wireshark: not-affected natty_wireshark: not-affected oneiric_wireshark: not-affected devel_wireshark: not-affected Patches_ethereal: upstream_ethereal: DNE dapper_ethereal: ignored (reached end-of-life) feisty_ethereal: DNE gutsy_ethereal: DNE hardy_ethereal: DNE intrepid_ethereal: DNE jaunty_ethereal: DNE karmic_ethereal: DNE lucid_ethereal: DNE maverick_ethereal: DNE natty_ethereal: DNE oneiric_ethereal: DNE devel_ethereal: DNE