CVE-2009-0599Improper Restriction of Operations within the Bounds of a Memory Buffer in Wireshark

Severity
5.0MEDIUMNVD
EPSS
1.5%
top 18.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16
Latest updateMay 2

Description

Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.0.6-1 (bookworm)
Debianwireshark/wireshark< 1.0.6-1+3
NVDwireshark/wireshark9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6cj3-ff8f-838h: Buffer overflow in wiretap/netscreen2022-05-02
OSV
CVE-2009-0599: Buffer overflow in wiretap/netscreen2009-02-16

📋Vendor Advisories

2
Red Hat
wireshark: buffer overflows in NetScreen snoop file reader2009-02-06
Debian
CVE-2009-0599: wireshark - Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows ...2009

💬Community

1
Bugzilla
CVE-2009-0599 wireshark: buffer overflows in NetScreen snoop file reader2009-02-17