CVE-2009-3829
published 2009-10-30CVE-2009-3829: Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash)…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.08%
92.6th percentile
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.2-1 (bookworm) | wireshark 1.2.2-1 (bookworm) |
| wireshark | wireshark | <= 1.2.1 | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: unsigned integer wrap vulnerability in ERF reader (VU#676492)
vendor_redhat·2009-10-05·CVSS 9.3
CVE-2009-3829 [CRITICAL] wireshark: unsigned integer wrap vulnerability in ERF reader (VU#676492)
wireshark: unsigned integer wrap vulnerability in ERF reader (VU#676492)
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
Debian
CVE-2009-3829: wireshark - Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attack...
vendor_debian·2009·CVSS 9.3
CVE-2009-3829 [CRITICAL] CVE-2009-3829: wireshark - Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attack...
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
Scope: local
bookworm: resolved (fixed in 1.2.2-1)
bullseye: resolved (fixed in 1.2.2-1)
forky: resolved (fixed in 1.2.2-1)
sid: resolved (fixed in 1.2.2-1)
trixie: resolved (fixed in 1.2.2-1)
GHSA
GHSA-qq8v-pv8c-pf8x: Integer overflow in wiretap/erf
ghsa_unreviewed·2022-05-02
CVE-2009-3829 [HIGH] GHSA-qq8v-pv8c-pf8x: Integer overflow in wiretap/erf
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
OSV
CVE-2009-3829: Integer overflow in wiretap/erf
osv·2009-10-30·CVSS 9.3
CVE-2009-3829 [CRITICAL] CVE-2009-3829: Integer overflow in wiretap/erf
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
No detection rules found.
No public exploits indexed.
http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&pathrev=29364http://secunia.com/advisories/37409http://secunia.com/advisories/37477http://www.debian.org/security/2009/dsa-1942http://www.kb.cert.org/vuls/id/676492http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3849https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9945http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&pathrev=29364http://secunia.com/advisories/37409http://secunia.com/advisories/37477http://www.debian.org/security/2009/dsa-1942http://www.kb.cert.org/vuls/id/676492http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3849https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5979https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9945
2009-10-30
Published