CVE-2009-2563Wireshark vulnerability

7 documents6 sources
Severity
7.1HIGHNVD
EPSS
1.3%
top 20.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 21
Latest updateMay 2

Description

Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.2.1-1 (bookworm)
Debianwireshark/wireshark< 1.2.1-1+3
NVDwireshark/wireshark4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r5fm-q7h8-jqhr: Unspecified vulnerability in the Infiniband dissector in Wireshark 12022-05-02
OSV
CVE-2009-2563: Unspecified vulnerability in the Infiniband dissector in Wireshark 12009-07-21

📋Vendor Advisories

2
Red Hat
Wireshark: Null-ptr dereference in the InfiniBand dissector2009-07-20
Debian
CVE-2009-2563: wireshark - Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through...2009

💬Community

2
Bugzilla
CVE-2009-2620 firebird-superserver: NULL ptr dereference (DoS) by handling auxiliary connection(s)2009-07-29
Bugzilla
CVE-2009-2563 Wireshark: Null-ptr dereference in the InfiniBand dissector2009-07-21