Unrated severityNVD Advisory· Published Sep 2, 2008· Updated Apr 23, 2026
CVE-2008-3146
CVE-2008-3146
Description
Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.
Affected products
17cpe:2.3:a:wireshark:wireshark:0.9.7:*:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:wireshark:wireshark:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.1:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.2:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.5:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.6:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.6a:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.7:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:0.99.8:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- bugs.wireshark.org/bugzilla/show_bug.cginvdVendor Advisory
- secunia.com/advisories/31687nvdVendor Advisory
- secunia.com/advisories/31864nvdVendor Advisory
- secunia.com/advisories/31886nvdVendor Advisory
- secunia.com/advisories/32028nvdVendor Advisory
- secunia.com/advisories/32091nvdVendor Advisory
- www.vupen.com/english/advisories/2008/2773nvdVendor Advisory
- www.wireshark.org/security/wnpa-sec-2008-05.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlnvd
- security.gentoo.org/glsa/glsa-200809-17.xmlnvd
- support.avaya.com/elmodocs2/security/ASA-2008-392.htmnvd
- wiki.rpath.com/wiki/Advisories:rPSA-2008-0278nvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2008-0890.htmlnvd
- www.securityfocus.com/archive/1/496487/100/0/threadednvd
- www.securitytracker.com/idnvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10624nvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00713.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2008-September/msg00715.htmlnvd
News mentions
0No linked articles in our index yet.