CVE-2009-4378Wireshark vulnerability

4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 32.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 21
Latest updateMay 2

Description

The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime."

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDwireshark/wireshark5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qm85-wjm8-m9v8: The IPMI dissector in Wireshark 12022-05-02

📋Vendor Advisories

1
Debian
CVE-2009-4378: wireshark - The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote att...2009

💬Community

1
Bugzilla
CVE-2009-4377 wireshark: invalid pointer dereference in SMB/SMB2 dissectors2009-12-22