CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:N/A:P
AI Score
Confidence
Low
EPSS
Percentile
82.9%
The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.
Vendor | Product | Version | CPE |
---|---|---|---|
wireshark | wireshark | 0.9.2 | cpe:2.3:a:wireshark:wireshark:0.9.2:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.5 | cpe:2.3:a:wireshark:wireshark:0.9.5:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.6 | cpe:2.3:a:wireshark:wireshark:0.9.6:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.7 | cpe:2.3:a:wireshark:wireshark:0.9.7:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.8 | cpe:2.3:a:wireshark:wireshark:0.9.8:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.10 | cpe:2.3:a:wireshark:wireshark:0.9.10:*:*:*:*:*:*:* |
wireshark | wireshark | 0.9.14 | cpe:2.3:a:wireshark:wireshark:0.9.14:*:*:*:*:*:*:* |
wireshark | wireshark | 0.99 | cpe:2.3:a:wireshark:wireshark:0.99:*:*:*:*:*:*:* |
wireshark | wireshark | 0.99.0 | cpe:2.3:a:wireshark:wireshark:0.99.0:*:*:*:*:*:*:* |
wireshark | wireshark | 0.99.1 | cpe:2.3:a:wireshark:wireshark:0.99.1:*:*:*:*:*:*:* |
osvdb.org/61178
secunia.com/advisories/37842
secunia.com/advisories/37916
www.debian.org/security/2009/dsa-1983
www.mandriva.com/security/advisories?name=MDVSA-2010:031
www.securityfocus.com/bid/37407
www.securitytracker.com/id?1023374
www.vupen.com/english/advisories/2009/3596
www.wireshark.org/security/wnpa-sec-2009-09.html
bugs.wireshark.org/bugzilla/show_bug.cgi?id=4301
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9564
www.redhat.com/archives/fedora-package-announce/2009-December/msg01248.html