Analyst readout for executives and security teams
Plain-English summary
CVE-2008-1070 is a denial-of-service flaw in Wireshark’s SCTP packet dissector. A malformed packet can crash affected Wireshark versions, disrupting packet analysis and incident response workstations rather than directly compromising servers.
Executive priority
Treat this as a targeted reliability risk to security operations tooling. Patch where old Wireshark packages remain, especially in labs, monitoring stations, and incident response images.
Technical view
The CVE describes a crash in the SCTP dissector in Wireshark, formerly Ethereal, versions 0.99.5 through 0.99.7. The trigger is malformed packet data. The bundle does not provide CVSS, CWE, root-cause detail, or evidence of code execution.
Likely exposure
Exposure is most likely on analyst, network monitoring, troubleshooting, or security tooling systems running Wireshark/Ethereal 0.99.5 through 0.99.7 or distribution packages built from those versions.
Exploitation context
The provided sources say remote attackers can cause a crash via a malformed packet. KEV is false, and the bundle does not cite active exploitation, public exploit use, or broader compromise impact.
Researcher notes
The bundle supports malformed-packet denial of service in the SCTP dissector only. Affected version detail comes from the CVE description; vendor advisories should be used for package-specific fixed versions.
Mitigation direction
- Inventory Wireshark/Ethereal installations and package versions.
- Update affected installations using Wireshark or operating-system vendor guidance.
- Prioritize analyst workstations and monitoring hosts that inspect SCTP traffic.
- Avoid opening untrusted packet captures with affected versions until updated.
Validation and detection
- Confirm no systems run Wireshark/Ethereal 0.99.5 through 0.99.7.
- Check distribution advisories for fixed package status.
- Verify packet-analysis workflows use updated binaries.
- Review crash reports for Wireshark/tshark failures during SCTP analysis.
Public sources used
Based on public source material and reviewed before publication.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2008-1070 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- GLSA-200803-32CVE reference · vendor-advisory, x_refsource_GENTOO
- RHSA-2008:0890CVE reference · vendor-advisory, x_refsource_REDHAT
- oval:org.mitre.oval:def:11378CVE reference · vdb-entry, signature
- http://www.wireshark.org/security/wnpa-sec-2008-01.htmlCVE reference · x_refsource_CONFIRM
- FEDORA-2008-3040CVE reference · vendor-advisory, x_refsource_FEDORA
- 29188CVE reference · third-party-advisory, x_refsource_SECUNIA
- 29242CVE reference · third-party-advisory, x_refsource_SECUNIA
- 29511CVE reference · third-party-advisory, x_refsource_SECUNIA
- SUSE-SR:2008:005CVE reference · vendor-advisory, x_refsource_SUSE
- 20080229 rPSA-2008-0092-1 tshark wiresharkCVE reference · mailing-list, x_refsource_BUGTRAQ
- 1019515CVE reference · vdb-entry, x_refsource_SECTRACK
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0092CVE reference · x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-392.htmCVE reference · x_refsource_CONFIRM
- 32091CVE reference · third-party-advisory, x_refsource_SECUNIA
- 29736CVE reference · third-party-advisory, x_refsource_SECUNIA
- ADV-2008-2773CVE reference · vdb-entry, x_refsource_VUPEN
- https://issues.rpath.com/browse/RPL-2296CVE reference · x_refsource_CONFIRM
- ADV-2008-0704CVE reference · vdb-entry, x_refsource_VUPEN
- 28025CVE reference · vdb-entry, x_refsource_BID
- MDVSA-2008:057CVE reference · vendor-advisory, x_refsource_MANDRIVA
- oval:org.mitre.oval:def:14995CVE reference · vdb-entry, signature
- 29156CVE reference · third-party-advisory, x_refsource_SECUNIA
- FEDORA-2008-2941CVE reference · vendor-advisory, x_refsource_FEDORA
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
