Vulnerability record · CVE-2008-1562 · published 31 March 2008
CVE-2008-1562: Wireshark LDAP dissector malformed packet denial of service
Wireshark · Wireshark
The LDAP dissector in Wireshark 0.99.2 through 0.99.8 fails to properly validate malformed packets, causing the application to crash. This is a distinct issue from CVE-2006-5740. It matters because a crafted packet can take down a capture session, disrupting network monitoring and analysis.
Description
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is a remote unauthenticated denial of service with medium CVSS severity and no confirmed in-the-wild exploitation, though EPSS is high.
What it is
The LDAP dissector in Wireshark 0.99.2 through 0.99.8 fails to properly validate malformed packets, causing the application to crash. This is a distinct issue from CVE-2006-5740. It matters because a crafted packet can take down a capture session, disrupting network monitoring and analysis.
Impact
An attacker can crash the Wireshark process, causing a denial of service. There is no reported loss of confidentiality or integrity, only availability.
Attack surface
The flaw is reached over the network via a malformed LDAP packet processed by the dissector. No authentication or user interaction is required beyond the victim capturing or opening the malicious traffic.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record. EPSS shows a 30-day probability of 0.50693 (98.865th percentile), indicating elevated predicted exploitation activity.
What to do
- Upgrade Wireshark to a version later than 0.99.8 that contains the LDAP dissector fix.
- Apply vendor patches from Red Hat, openSUSE, Gentoo, Mandriva, rPath or Avaya as applicable to your distribution.
- Avoid capturing or opening untrusted packet captures with affected Wireshark versions until patched.
- Restrict network capture exposure to trusted segments where feasible to limit malformed LDAP traffic reaching the dissector.
Detection
- Monitor for Wireshark process crashes or abnormal terminations correlated with LDAP traffic capture.
- Review packet captures for malformed LDAP packets targeting the dissector.
- Check installed Wireshark versions against the 0.99.2 through 0.99.8 affected range.
- Correlate crash reports or core dumps from analysis hosts with LDAP protocol decoding.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.