CVE-2009-2562
published 2009-07-21CVE-2009-2562: Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.93%
85.6th percentile
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.1-1 (bookworm) | wireshark 1.2.1-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8cfm-h4m4-f6q9: Unspecified vulnerability in the AFS dissector in Wireshark 0
ghsa_unreviewed·2022-05-02
CVE-2009-2562 [MEDIUM] GHSA-8cfm-h4m4-f6q9: Unspecified vulnerability in the AFS dissector in Wireshark 0
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
OSV
CVE-2009-2562: Unspecified vulnerability in the AFS dissector in Wireshark 0
osv·2009-07-21·CVSS 5.0
CVE-2009-2562 [MEDIUM] CVE-2009-2562: Unspecified vulnerability in the AFS dissector in Wireshark 0
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Red Hat
Wireshark: Integer overflow in the AFS dissector
vendor_redhat·2009-07-20·CVSS 5.0
CVE-2009-2562 [MEDIUM] CWE-190 Wireshark: Integer overflow in the AFS dissector
Wireshark: Integer overflow in the AFS dissector
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Debian
CVE-2009-2562: wireshark - Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 ...
vendor_debian·2009·CVSS 5.0
CVE-2009-2562 [MEDIUM] CVE-2009-2562: wireshark - Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 ...
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2562 Wireshark: Integer overflow in the AFS dissector
bugzilla·2009-07-21·CVSS 5.0
CVE-2009-2562 [MEDIUM] CVE-2009-2562 Wireshark: Integer overflow in the AFS dissector
CVE-2009-2562 Wireshark: Integer overflow in the AFS dissector
An integer overflow flaw, leading to heap-based buffer overflow was found
in the Wiresharks's AFS dissector. A remote attacker could provide
a specially-crafted AFS packet capture file, which once opened by an
unsuspecting user would lead to denial of service (Wireshark crash).
References:
http://www.wireshark.org/security/wnpa-sec-2009-04.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564
Reproducer:
https://bugs.wireshark.org/bugzilla/attachment.cgi?id=3167
Upstream patch:
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-afs.c?r1=28815&r2=28814&pathrev=28815&view=patch
Discussion:
This issue affects the versions of the Wireshark package, as shipped
with Red Hat Enteprise Linux 3, 4, and 5.
Th
arXiv
MARFCAT: Transitioning to Binary and Larger Data Sets of SATE IV
arxiv_fulltext·2013-05-10
MARFCAT: Transitioning to Binary and Larger Data Sets of SATE IV
MARFCAT: Transitioning to Binary and Larger Data Sets of
MARFCAT: A MARF Approach to
Serguei A. Mokhov^1,2, Joey Paquet^1, Mourad Debbabi^1, Yankui Sun^2
^1Concordia University
Montreal, QC, Canada
mokhov,paquet,[email protected]
^2Tsinghua University
Beijing, China
[email protected]
Mokhov, Paquet, Debbabi, Sun
## Abstract
We present a second iteration of a machine learning approach to static
code analysis and fingerprinting for weaknesses related to security, software engineering,
and others using the open-source framework and the application
based on it for the NIST's static analysis tool exposition workshop's data
sets that include additional test cases, including new large synthetic cases.
To aid detection of weak or vulnerable code, including source or binar
http://secunia.com/advisories/35884http://secunia.com/advisories/37477http://www.debian.org/security/2009/dsa-1942http://www.mandriva.com/security/advisories?name=MDVSA-2009:194http://www.openwall.com/lists/oss-security/2009/09/17/15http://www.openwall.com/lists/oss-security/2009/09/18/2http://www.securityfocus.com/bid/35748http://www.vupen.com/english/advisories/2009/1970http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-04.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-05.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5625http://secunia.com/advisories/35884http://secunia.com/advisories/37477http://www.debian.org/security/2009/dsa-1942http://www.mandriva.com/security/advisories?name=MDVSA-2009:194http://www.openwall.com/lists/oss-security/2009/09/17/15http://www.openwall.com/lists/oss-security/2009/09/18/2http://www.securityfocus.com/bid/35748http://www.vupen.com/english/advisories/2009/1970http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-04.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-05.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3564https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11643https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5625
2009-07-21
Published