CVE-2010-2284
published 2010-06-15CVE-2010-2284: Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
PriorityP431high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.81%
53.2th percentile
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.9-1 (bookworm) | wireshark 1.2.9-1 (bookworm) |
| debian | wireshark | < wireshark 1.2.10-1 (bookworm) | wireshark 1.2.10-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: ASN.1 BER dissector stack overrun
vendor_redhat·2010-06-09·CVSS 8.3
CVE-2010-2284 [HIGH] wireshark: ASN.1 BER dissector stack overrun
wireshark: ASN.1 BER dissector stack overrun
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2284: wireshark - Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 a...
vendor_debian·2010·CVSS 8.3
CVE-2010-2284 [HIGH] CVE-2010-2284: wireshark - Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 a...
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.2.9-1)
Debian
CVE-2010-2994: wireshark - Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 thro...
vendor_debian·2010·CVSS 8.3
CVE-2010-2994 [HIGH] CVE-2010-2994: wireshark - Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 thro...
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
Scope: local
bookworm: resolved (fixed in 1.2.10-1)
bullseye: resolved (fixed in 1.2.10-1)
forky: resolved (fixed in 1.2.10-1)
sid: resolved (fixed in 1.2.10-1)
trixie: resolved (fixed in 1.2.10-1)
GHSA
GHSA-5x4j-j8vc-crqg: Buffer overflow in the ASN
ghsa_unreviewed·2022-05-17
CVE-2010-2284 [HIGH] CWE-119 GHSA-5x4j-j8vc-crqg: Buffer overflow in the ASN
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
GHSA
GHSA-56g9-w9r4-jc7v: Stack-based buffer overflow in the ASN
ghsa_unreviewed·2022-05-17·CVSS 8.3
CVE-2010-2994 [HIGH] CWE-119 GHSA-56g9-w9r4-jc7v: Stack-based buffer overflow in the ASN
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
OSV
CVE-2010-2994: Stack-based buffer overflow in the ASN
osv·2010-08-13·CVSS 8.3
CVE-2010-2994 [HIGH] CVE-2010-2994: Stack-based buffer overflow in the ASN
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
OSV
CVE-2010-2284: Buffer overflow in the ASN
osv·2010-06-15·CVSS 8.3
CVE-2010-2284 [HIGH] CVE-2010-2284: Buffer overflow in the ASN
Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.mandriva.com/security/advisories?name=MDVSA-2010:144http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11888http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.mandriva.com/security/advisories?name=MDVSA-2010:144http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11888
2010-06-15
Published