CVE-2010-2995
published 2010-08-13CVE-2010-2995: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial…
PriorityP343critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.73%
93.2th percentile
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2.10-1 (bookworm) | wireshark 1.2.10-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wireshark: SigComp UDVM dissector buffer overruns
vendor_redhat·2010-06-09·CVSS 8.3
CVE-2010-2995 [HIGH] wireshark: SigComp UDVM dissector buffer overruns
wireshark: SigComp UDVM dissector buffer overruns
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2995: wireshark - The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 th...
vendor_debian·2010·CVSS 8.3
CVE-2010-2995 [HIGH] CVE-2010-2995: wireshark - The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 th...
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
Scope: local
bookworm: resolved (fixed in 1.2.10-1)
bullseye: resolved (fixed in 1.2.10-1)
forky: resolved (fixed in 1.2.10-1)
sid: resolved (fixed in 1.2.10-1)
trixie: resolved (fixed in 1.2.10-1)
GHSA
GHSA-cxh7-25p5-8q7m: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
ghsa_unreviewed·2022-05-17·CVSS 8.3
CVE-2010-2995 [HIGH] GHSA-cxh7-25p5-8q7m: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
OSV
CVE-2010-2995: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
osv·2010-08-13·CVSS 8.3
CVE-2010-2995 [HIGH] CVE-2010-2995: The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0
The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities
bugzilla·2010-08-12·CVSS 5.0
CVE-2010-2992 [MEDIUM] CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities
CVE-2010-2992 CVE-2010-2993 wireshark: 1.2.10 corrects multiple vulnerabilities
Upstream has released wireshark 1.2.10 [1] which corrects a number of vulnerabilities:
The SigComp Universal Decompressor Virtual Machine could overrun a buffer. (Bug 4867)
Versions affected: 0.10.8 to 1.0.14, 1.2.0 to 1.2.9
CVE-2010-2995
Due to a regression the ASN.1 BER dissector could exhaust stack memory. (Bug 4984)
Versions affected: 0.10.13 to 1.0.14, 1.2.0 to 1.2.9
CVE-2010-2994
The GSM A RR dissector could crash. (Bug 4897)
Versions affected: 1.2.2 to 1.2.9 CVE-2010-2992
The IPMI dissector could go into an infinite loop. (Bug 5053)
Versions affected: 1.2.0 to 1.2.9 CVE-2010-2993
Current Fedora 12 and 13 are vulnerable to these issues. CVE-2010-2995 is already tracked via bug #604308 and CVE-2010-
Bugzilla
CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns
bugzilla·2010-06-15·CVSS 8.3
CVE-2010-2995 [HIGH] CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns
CVE-2010-2995 wireshark: SigComp UDVM dissector buffer overruns
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2287 to
the following vulnerability:
Name: CVE-2010-2287
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2287
Assigned: 20100614
Reference: MLIST:[oss-security] 20100610 CVE request for new wireshark vulnerabilities
Reference: URL: http://www.openwall.com/lists/oss-security/2010/06/11/1
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2010-05.html
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2010-06.html
Reference: MANDRIVA:MDVSA-2010:113
Reference: URL: http://www.mandriva.com/security/advisories?name=MDVSA-2010:113
Reference: SECUNIA:40112
Reference: URL: http://secunia.com/advisories/40112
Reference: VUPEN:ADV-
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4867https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12049http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42877http://secunia.com/advisories/43068http://www.vupen.com/english/advisories/2011/0076http://www.vupen.com/english/advisories/2011/0212http://www.wireshark.org/docs/relnotes/wireshark-1.2.10.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4867https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12049
2010-08-13
Published