CVE-2010-2287
published 2010-06-15CVE-2010-2287: Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact…
PriorityP431high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
0.81%
52.6th percentile
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.10-1 (bookworm) | wireshark 1.2.10-1 (bookworm) |
| debian | wireshark | < wireshark 1.2.9-1 (bookworm) | wireshark 1.2.9-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: SigComp UDVM dissector buffer overruns
vendor_redhat·2010-06-09·CVSS 8.3
CVE-2010-2995 [HIGH] wireshark: SigComp UDVM dissector buffer overruns
wireshark: SigComp UDVM dissector buffer overruns
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Red Hat
wireshark: SigComp UDVM dissector buffer overruns
vendor_redhat·2010-06-09·CVSS 8.3
CVE-2010-2287 [HIGH] wireshark: SigComp UDVM dissector buffer overruns
wireshark: SigComp UDVM dissector buffer overruns
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2995: wireshark - The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 th...
vendor_debian·2010·CVSS 8.3
CVE-2010-2995 [HIGH] CVE-2010-2995: wireshark - The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 th...
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
Scope: local
bookworm: resolved (fixed in 1.2.10-1)
bullseye: resolved (fixed in 1.2.10-1)
forky: resolved (fixed in 1.2.10-1)
sid: resolved (fixed in 1.2.10-1)
trixie: resolved (fixed in 1.2.10-1)
Debian
CVE-2010-2287: wireshark - Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector ...
vendor_debian·2010·CVSS 8.3
CVE-2010-2287 [HIGH] CVE-2010-2287: wireshark - Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector ...
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
Scope: local
bookworm: resolved (fixed in 1.2.9-1)
bullseye: resolved (fixed in 1.2.9-1)
forky: resolved (fixed in 1.2.9-1)
sid: resolved (fixed in 1.2.9-1)
trixie: resolved (fixed in 1.2.9-1)
GHSA
GHSA-cxh7-25p5-8q7m: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
ghsa_unreviewed·2022-05-17·CVSS 8.3
CVE-2010-2995 [HIGH] GHSA-cxh7-25p5-8q7m: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
GHSA
GHSA-wj3w-79hv-x498: Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
ghsa_unreviewed·2022-05-17
CVE-2010-2287 [HIGH] CWE-119 GHSA-wj3w-79hv-x498: Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
OSV
CVE-2010-2995: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
osv·2010-08-13·CVSS 8.3
CVE-2010-2995 [HIGH] CVE-2010-2995: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
OSV
CVE-2010-2287: Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
osv·2010-06-15·CVSS 8.3
CVE-2010-2287 [HIGH] CVE-2010-2287: Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0
Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.mandriva.com/security/advisories?name=MDVSA-2010:144http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11836http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40112http://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.mandriva.com/security/advisories?name=MDVSA-2010:113http://www.mandriva.com/security/advisories?name=MDVSA-2010:144http://www.openwall.com/lists/oss-security/2010/06/11/1http://www.securityfocus.com/bid/40728http://www.vupen.com/english/advisories/2010/1418http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/security/wnpa-sec-2010-05.htmlhttp://www.wireshark.org/security/wnpa-sec-2010-06.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11836
2010-06-15
Published