CVE-2009-4377Wireshark vulnerability

6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.5%
top 18.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 21
Latest updateMay 2

Description

The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.2.5-1 (bookworm)
Debianwireshark/wireshark< 1.2.5-1+3
NVDwireshark/wireshark36 versions+35

🔴Vulnerability Details

2
GHSA
GHSA-wqc7-2v82-hg6w: The (1) SMB and (2) SMB2 dissectors in Wireshark 02022-05-02
OSV
CVE-2009-4377: The (1) SMB and (2) SMB2 dissectors in Wireshark 02009-12-21

📋Vendor Advisories

2
Red Hat
wireshark: invalid pointer dereference in SMB/SMB2 dissectors2009-12-17
Debian
CVE-2009-4377: wireshark - The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remot...2009

💬Community

1
Bugzilla
CVE-2009-4377 wireshark: invalid pointer dereference in SMB/SMB2 dissectors2009-12-22