CVE-2009-2563
published 2009-07-21CVE-2009-2563: Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause…
PriorityP423high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.60%
83.6th percentile
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.1-1 (bookworm) | wireshark 1.2.1-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.2.1-1 | 1.2.1-1 |
| wireshark | wireshark | >= 0 < 1.2.1-1 | 1.2.1-1 |
| wireshark | wireshark | >= 0 < 1.2.1-1 | 1.2.1-1 |
| wireshark | wireshark | >= 0 < 1.2.1-1 | 1.2.1-1 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r5fm-q7h8-jqhr: Unspecified vulnerability in the Infiniband dissector in Wireshark 1
ghsa_unreviewed·2022-05-02
CVE-2009-2563 [HIGH] GHSA-r5fm-q7h8-jqhr: Unspecified vulnerability in the Infiniband dissector in Wireshark 1
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
OSV
CVE-2009-2563: Unspecified vulnerability in the Infiniband dissector in Wireshark 1
osv·2009-07-21·CVSS 7.1
CVE-2009-2563 [HIGH] CVE-2009-2563: Unspecified vulnerability in the Infiniband dissector in Wireshark 1
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
Red Hat
Wireshark: Null-ptr dereference in the InfiniBand dissector
vendor_redhat·2009-07-20·CVSS 7.1
CVE-2009-2563 [HIGH] Wireshark: Null-ptr dereference in the InfiniBand dissector
Wireshark: Null-ptr dereference in the InfiniBand dissector
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
Debian
CVE-2009-2563: wireshark - Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through...
vendor_debian·2009·CVSS 7.1
CVE-2009-2563 [HIGH] CVE-2009-2563: wireshark - Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through...
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-2620 firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s)
bugzilla·2009-07-29·CVSS 5.0
CVE-2009-2620 [MEDIUM] CVE-2009-2620 firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s)
CVE-2009-2620 firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s)
A NULL pointer dereference flaw was found in the way Superserver used to
handle (accept and reply to) auxiliary connections. A remote attacker
could initiate a specially-crafted auxiliary connection request against
the Firebird's Superserver, which would lead to denial of service
(firebird crash).
References:
http://www.coresecurity.com/content/firebird-sql-dos
http://www.securityfocus.com/bid/35842/info
Reproducer:
http://www.securityfocus.com/data/vulnerabilities/exploits/35842.py
Upstream changesets:
http://tracker.firebirdsql.org/browse/CORE-2563 (search for "Version control")
Patch:
http://firebird.cvs.sourceforge.net/viewvc/firebird/firebird2/src/remote/server.cpp?r1=1.158.2.6&r2=1
Bugzilla
CVE-2009-2563 Wireshark: Null-ptr dereference in the InfiniBand dissector
bugzilla·2009-07-21·CVSS 7.1
CVE-2009-2563 [HIGH] CVE-2009-2563 Wireshark: Null-ptr dereference in the InfiniBand dissector
CVE-2009-2563 Wireshark: Null-ptr dereference in the InfiniBand dissector
A NULL pointer dereference flaw was found in the Wireshark's InfiniBand
dissector. A remote attacker could provide a specially-crafted InfiniBand
packet capture file, which once opened by an unsuspecting user would
lead to denial of service (Wireshark crash).
References:
http://www.wireshark.org/security/wnpa-sec-2009-04.html
Upstream patch:
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-infiniband.c?r1=28839&r2=28838&pathrev=28839&view=patch
Discussion:
This issue affects the versions of the wireshark package, as shipped
with Red Hat Enterprise Linux 3, 4, and 5.
This issue affects the versions of the wireshark package, as shipped
with Fedora releases of 10, 11, and Rawhide.
---
MITRE's CV
http://secunia.com/advisories/35884http://www.mandriva.com/security/advisories?name=MDVSA-2009:194http://www.mandriva.com/security/advisories?name=MDVSA-2010:031http://www.openwall.com/lists/oss-security/2009/09/17/15http://www.openwall.com/lists/oss-security/2009/09/18/2http://www.securityfocus.com/bid/35748http://www.vupen.com/english/advisories/2009/1970http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-04.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-05.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11210https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6321http://secunia.com/advisories/35884http://www.mandriva.com/security/advisories?name=MDVSA-2009:194http://www.mandriva.com/security/advisories?name=MDVSA-2010:031http://www.openwall.com/lists/oss-security/2009/09/17/15http://www.openwall.com/lists/oss-security/2009/09/18/2http://www.securityfocus.com/bid/35748http://www.vupen.com/english/advisories/2009/1970http://www.wireshark.org/docs/relnotes/wireshark-1.0.9.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-04.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-05.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11210https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6321
2009-07-21
Published