CVE-2009-3549
published 2009-10-30CVE-2009-3549: packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.60%
83.7th percentile
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.3-1 (bookworm) | wireshark 1.2.3-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.2.3-1 | 1.2.3-1 |
| wireshark | wireshark | >= 0 < 1.2.3-1 | 1.2.3-1 |
| wireshark | wireshark | >= 0 < 1.2.3-1 | 1.2.3-1 |
| wireshark | wireshark | >= 0 < 1.2.3-1 | 1.2.3-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v6mq-p8pv-vq8r: packet-paltalk
ghsa_unreviewed·2022-05-02
CVE-2009-3549 [MEDIUM] CWE-20 GHSA-v6mq-p8pv-vq8r: packet-paltalk
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
OSV
CVE-2009-3549: packet-paltalk
osv·2009-10-30·CVSS 5.0
CVE-2009-3549 [MEDIUM] CVE-2009-3549: packet-paltalk
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Red Hat
Wireshark: Invalid pointer dereference in the Paltalk dissector
vendor_redhat·2009-10-27·CVSS 5.0
CVE-2009-3549 [MEDIUM] Wireshark: Invalid pointer dereference in the Paltalk dissector
Wireshark: Invalid pointer dereference in the Paltalk dissector
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Statement: Not vulnerable. This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 3, 4, or 5.
Debian
CVE-2009-3549: wireshark - packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on S...
vendor_debian·2009·CVSS 5.0
CVE-2009-3549 [MEDIUM] CVE-2009-3549: wireshark - packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on S...
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid: resolved (fixed in 1.2.3-1)
trixie: resolved (fixed in 1.2.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3549 Wireshark: Invalid pointer dereference in the Paltalk dissector
bugzilla·2009-10-27·CVSS 5.0
CVE-2009-3549 [MEDIUM] CVE-2009-3549 Wireshark: Invalid pointer dereference in the Paltalk dissector
CVE-2009-3549 Wireshark: Invalid pointer dereference in the Paltalk dissector
An invalid pointer dereference flaw was found in the Wireshark's Paltalk
dissector. A remote attacker could provide a specially-crafted Paltalk
packet capture file, which once opened by an unsuspecting user would
lead to denial of service (Wireshark crash).
References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-paltalk.c?view=log&pathrev=29064
Upstream patch:
http://anonsvn.wireshark.org/viewvc/trunk/epan/dissectors/packet-paltalk.c?r1=28437&r2=29064&pathrev=29064&view=patch
Discussion:
This issue does NOT affect the versions of the wireshark package, as shipped
with Red Hat Enterprise Linux 3, 4, or 5.
This issue affects the ver
arXiv
Automated Software Vulnerability Static Code Analysis Using Generative Pre-Trained Transformer Models
arxiv_fulltext·2024-07-31
Automated Software Vulnerability Static Code Analysis Using Generative Pre-Trained Transformer Models
## Abstract
Generative Pre-Trained Transformer models have been shown to be surprisingly effective at a variety of natural language processing tasks -- including generating computer code. However, in general GPT models have been shown to not be incredibly effective at handling specific computational tasks (such as evaluating mathematical functions).
In this study, we evaluate the effectiveness of open source GPT models, with no fine-tuning, and with context introduced by the langchain and localGPT Large Language Model (LLM) framework, for the task of automatic identification of the presence of vulnerable code syntax (specifically targeting C and C++ source code). This task is evaluated on a selection of 36 source code examples from the NIST SARD dataset, which are specifically curated to
http://secunia.com/advisories/37175http://secunia.com/advisories/37409http://www.securityfocus.com/bid/36846http://www.vupen.com/english/advisories/2009/3061http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-07.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689https://exchange.xforce.ibmcloud.com/vulnerabilities/54016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6391http://secunia.com/advisories/37175http://secunia.com/advisories/37409http://www.securityfocus.com/bid/36846http://www.vupen.com/english/advisories/2009/3061http://www.wireshark.org/docs/relnotes/wireshark-1.2.3.htmlhttp://www.wireshark.org/security/wnpa-sec-2009-07.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3689https://exchange.xforce.ibmcloud.com/vulnerabilities/54016https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6391
2009-10-30
Published