CVE-2010-2994
published 2010-08-13CVE-2010-2994: Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.43%
82.5th percentile
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.10-1 (bookworm) | wireshark 1.2.10-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-56g9-w9r4-jc7v: Stack-based buffer overflow in the ASN
ghsa_unreviewed·2022-05-17·CVSS 8.3
CVE-2010-2994 [HIGH] CWE-119 GHSA-56g9-w9r4-jc7v: Stack-based buffer overflow in the ASN
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
OSV
CVE-2010-2994: Stack-based buffer overflow in the ASN
osv·2010-08-13·CVSS 8.3
CVE-2010-2994 [HIGH] CVE-2010-2994: Stack-based buffer overflow in the ASN
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
Debian
CVE-2010-2994: wireshark - Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 thro...
vendor_debian·2010·CVSS 8.3
CVE-2010-2994 [HIGH] CVE-2010-2994: wireshark - Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 thro...
Stack-based buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.14 and 1.2.0 through 1.2.9 has unknown impact and remote attack vectors. NOTE: this issue exists because of a CVE-2010-2284 regression.
Scope: local
bookworm: resolved (fixed in 1.2.10-1)
bullseye: resolved (fixed in 1.2.10-1)
forky: resolved (fixed in 1.2.10-1)
sid: resolved (fixed in 1.2.10-1)
trixie: resolved (fixed in 1.2.10-1)
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UPDATE
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UPDATE"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004461; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mit
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid DELETE
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid DELETE"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004459; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid ASCII
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid ASCII"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004460; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid INSERT
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid INSERT"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004458; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UNION SELECT
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid UNION SELECT"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004457; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-2994 [HIGH] ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid SELECT
ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS DGNews SQL Injection Attempt -- news.php newsid SELECT"; flow:established,to_server; http.uri; content:"/news.php?"; nocase; content:"newsid="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-2994; reference:url,www.securityfocus.com/bid/24212; classtype:web-application-attack; sid:2004456; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12047http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12047
2010-08-13
Published