CVE-2010-2286
published 2010-06-15CVE-2010-2286: The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a…
PriorityP411low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
1.12%
62.8th percentile
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.9-1 (bookworm) | wireshark 1.2.9-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: SigComp UDVM dissector infinite loop
vendor_redhat·2010-06-09·CVSS 3.3
CVE-2010-2286 [LOW] CWE-835 wireshark: SigComp UDVM dissector infinite loop
wireshark: SigComp UDVM dissector infinite loop
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2286: wireshark - The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7...
vendor_debian·2010·CVSS 3.3
CVE-2010-2286 [LOW] CVE-2010-2286: wireshark - The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7...
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.2.9-1)
GHSA
GHSA-mvxw-3948-pfh6: The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
ghsa_unreviewed·2022-05-17
CVE-2010-2286 [LOW] GHSA-mvxw-3948-pfh6: The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
OSV
CVE-2010-2286: The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
osv·2010-06-15·CVSS 3.3
CVE-2010-2286 [LOW] CVE-2010-2286: The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11792http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11792
2010-06-15
Published