Lucene search

K
cveMitreCVE-2010-2995
HistoryAug 13, 2010 - 6:43 p.m.

CVE-2010-2995

2010-08-1318:43:27
CWE-189
mitre
web.nvd.nist.gov
41
wireshark
sigcomp
udvm
remote attackers
denial of service
arbitrary code
buffer overflow
cve-2010-2995

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.516

Percentile

97.6%

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

Affected configurations

Nvd
Node
wiresharkwiresharkMatch0.10.8
OR
wiresharkwiresharkMatch0.10.9
OR
wiresharkwiresharkMatch0.10.10
OR
wiresharkwiresharkMatch0.10.11
OR
wiresharkwiresharkMatch0.10.12
OR
wiresharkwiresharkMatch0.10.13
OR
wiresharkwiresharkMatch0.10.14
OR
wiresharkwiresharkMatch1.0.0
OR
wiresharkwiresharkMatch1.0.1
OR
wiresharkwiresharkMatch1.0.2
OR
wiresharkwiresharkMatch1.0.3
OR
wiresharkwiresharkMatch1.0.4
OR
wiresharkwiresharkMatch1.0.5
OR
wiresharkwiresharkMatch1.0.6
OR
wiresharkwiresharkMatch1.0.7
OR
wiresharkwiresharkMatch1.0.8
OR
wiresharkwiresharkMatch1.0.9
OR
wiresharkwiresharkMatch1.0.10
OR
wiresharkwiresharkMatch1.0.11
OR
wiresharkwiresharkMatch1.0.12
OR
wiresharkwiresharkMatch1.0.13
OR
wiresharkwiresharkMatch1.0.14
OR
wiresharkwiresharkMatch1.2
OR
wiresharkwiresharkMatch1.2.0
OR
wiresharkwiresharkMatch1.2.1
OR
wiresharkwiresharkMatch1.2.2
OR
wiresharkwiresharkMatch1.2.3
OR
wiresharkwiresharkMatch1.2.4
OR
wiresharkwiresharkMatch1.2.5
OR
wiresharkwiresharkMatch1.2.6
OR
wiresharkwiresharkMatch1.2.7
OR
wiresharkwiresharkMatch1.2.8
OR
wiresharkwiresharkMatch1.2.9
VendorProductVersionCPE
wiresharkwireshark0.10.8cpe:2.3:a:wireshark:wireshark:0.10.8:*:*:*:*:*:*:*
wiresharkwireshark0.10.9cpe:2.3:a:wireshark:wireshark:0.10.9:*:*:*:*:*:*:*
wiresharkwireshark0.10.10cpe:2.3:a:wireshark:wireshark:0.10.10:*:*:*:*:*:*:*
wiresharkwireshark0.10.11cpe:2.3:a:wireshark:wireshark:0.10.11:*:*:*:*:*:*:*
wiresharkwireshark0.10.12cpe:2.3:a:wireshark:wireshark:0.10.12:*:*:*:*:*:*:*
wiresharkwireshark0.10.13cpe:2.3:a:wireshark:wireshark:0.10.13:*:*:*:*:*:*:*
wiresharkwireshark0.10.14cpe:2.3:a:wireshark:wireshark:0.10.14:*:*:*:*:*:*:*
wiresharkwireshark1.0.0cpe:2.3:a:wireshark:wireshark:1.0.0:*:*:*:*:*:*:*
wiresharkwireshark1.0.1cpe:2.3:a:wireshark:wireshark:1.0.1:*:*:*:*:*:*:*
wiresharkwireshark1.0.2cpe:2.3:a:wireshark:wireshark:1.0.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.516

Percentile

97.6%