CVE-2009-4376Improper Restriction of Operations within the Bounds of a Memory Buffer in Wireshark

Severity
9.3CRITICALNVD
EPSS
3.1%
top 13.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 21
Latest updateMay 2

Description

Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.2.5-1 (bookworm)
Debianwireshark/wireshark< 1.2.5-1+3
NVDwireshark/wireshark5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-22hq-7p4w-fm2g: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 12022-05-02
OSV
CVE-2009-4376: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 12009-12-21

📋Vendor Advisories

1
Debian
CVE-2009-4376: wireshark - Buffer overflow in the daintree_sna_read function in the Daintree SNA file parse...2009

💬Community

1
Bugzilla
CVE-2009-4377 wireshark: invalid pointer dereference in SMB/SMB2 dissectors2009-12-22