Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-3242Reachable Assertion in Wireshark

7 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
3.2%
top 13.08%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 18
Latest updateMay 2

Description

Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.2.2-1 (bookworm)
Debianwireshark/wireshark< 1.2.2-1+3
NVDwireshark/wireshark1.2.0, 1.2.1+1

🔴Vulnerability Details

2
GHSA
GHSA-44gq-3r46-fprm: Unspecified vulnerability in packet2022-05-02
OSV
CVE-2009-3242: Unspecified vulnerability in packet2009-09-18

💥Exploits & PoCs

1
Exploit-DB
Wireshark 1.2.1 - GSM A RR Dissector packet.c Remote Denial of Service2009-09-15

📋Vendor Advisories

2
Red Hat
Wireshark: DoS (crash) in GSM A RR dissector2009-08-13
Debian
CVE-2009-3242: wireshark - Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2...2009

💬Community

1
Bugzilla
CVE-2009-3242 Wireshark: DoS (crash) in GSM A RR dissector2009-09-17