CVE-2009-4376
published 2009-12-21CVE-2009-4376: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.77%
93.3th percentile
Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.5-1 (bookworm) | wireshark 1.2.5-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.2.5-1 | 1.2.5-1 |
| wireshark | wireshark | >= 0 < 1.2.5-1 | 1.2.5-1 |
| wireshark | wireshark | >= 0 < 1.2.5-1 | 1.2.5-1 |
| wireshark | wireshark | >= 0 < 1.2.5-1 | 1.2.5-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-4376: wireshark - Buffer overflow in the daintree_sna_read function in the Daintree SNA file parse...
vendor_debian·2009·CVSS 9.3
CVE-2009-4376 [CRITICAL] CVE-2009-4376: wireshark - Buffer overflow in the daintree_sna_read function in the Daintree SNA file parse...
Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Scope: local
bookworm: resolved (fixed in 1.2.5-1)
bullseye: resolved (fixed in 1.2.5-1)
forky: resolved (fixed in 1.2.5-1)
sid: resolved (fixed in 1.2.5-1)
trixie: resolved (fixed in 1.2.5-1)
GHSA
GHSA-22hq-7p4w-fm2g: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1
ghsa_unreviewed·2022-05-02
CVE-2009-4376 [HIGH] CWE-119 GHSA-22hq-7p4w-fm2g: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1
Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
OSV
CVE-2009-4376: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1
osv·2009-12-21·CVSS 9.3
CVE-2009-4376 [CRITICAL] CVE-2009-4376: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1
Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
No detection rules found.
No public exploits indexed.
http://osvdb.org/61177http://secunia.com/advisories/37842http://secunia.com/advisories/37916http://www.securityfocus.com/bid/37407http://www.securitytracker.com/id?1023374http://www.vupen.com/english/advisories/2009/3596http://www.wireshark.org/security/wnpa-sec-2009-09.htmlhttps://bugs.wireshark.org/bugzilla/attachment.cgi?id=4022https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4294https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16435https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01248.htmlhttp://osvdb.org/61177http://secunia.com/advisories/37842http://secunia.com/advisories/37916http://www.securityfocus.com/bid/37407http://www.securitytracker.com/id?1023374http://www.vupen.com/english/advisories/2009/3596http://www.wireshark.org/security/wnpa-sec-2009-09.htmlhttps://bugs.wireshark.org/bugzilla/attachment.cgi?id=4022https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4294https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16435https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01248.html
2009-12-21
Published