CVE-2009-3549 — Improper Input Validation in Wireshark
Severity
5.0MEDIUMNVD
EPSS
1.3%
top 20.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 30
Latest updateJul 31
Description
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
2📄Research Papers
1arXiv▶
Automated Software Vulnerability Static Code Analysis Using Generative Pre-Trained Transformer Models↗2024-07-31