CVE Vulnerabilities

CVE-2009-4377

Published: Dec 21, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5.4 MODERATE
AV:A/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.

Affected Software

Name Vendor Start Version End Version
Wireshark Wireshark 0.9.2 (including) 0.9.2 (including)
Wireshark Wireshark 0.9.5 (including) 0.9.5 (including)
Wireshark Wireshark 0.9.6 (including) 0.9.6 (including)
Wireshark Wireshark 0.9.7 (including) 0.9.7 (including)
Wireshark Wireshark 0.9.8 (including) 0.9.8 (including)
Wireshark Wireshark 0.9.10 (including) 0.9.10 (including)
Wireshark Wireshark 0.9.14 (including) 0.9.14 (including)
Wireshark Wireshark 0.99 (including) 0.99 (including)
Wireshark Wireshark 0.99.0 (including) 0.99.0 (including)
Wireshark Wireshark 0.99.1 (including) 0.99.1 (including)
Wireshark Wireshark 0.99.2 (including) 0.99.2 (including)
Wireshark Wireshark 0.99.3 (including) 0.99.3 (including)
Wireshark Wireshark 0.99.4 (including) 0.99.4 (including)
Wireshark Wireshark 0.99.5 (including) 0.99.5 (including)
Wireshark Wireshark 0.99.6 (including) 0.99.6 (including)
Wireshark Wireshark 0.99.6a (including) 0.99.6a (including)
Wireshark Wireshark 0.99.7 (including) 0.99.7 (including)
Wireshark Wireshark 0.99.8 (including) 0.99.8 (including)
Wireshark Wireshark 0.99.9 (including) 0.99.9 (including)
Wireshark Wireshark 1.0 (including) 1.0 (including)
Wireshark Wireshark 1.0.0 (including) 1.0.0 (including)
Wireshark Wireshark 1.0.1 (including) 1.0.1 (including)
Wireshark Wireshark 1.0.2 (including) 1.0.2 (including)
Wireshark Wireshark 1.0.3 (including) 1.0.3 (including)
Wireshark Wireshark 1.0.4 (including) 1.0.4 (including)
Wireshark Wireshark 1.0.5 (including) 1.0.5 (including)
Wireshark Wireshark 1.0.6 (including) 1.0.6 (including)
Wireshark Wireshark 1.0.7 (including) 1.0.7 (including)
Wireshark Wireshark 1.0.8 (including) 1.0.8 (including)
Wireshark Wireshark 1.0.9 (including) 1.0.9 (including)
Wireshark Wireshark 1.2 (including) 1.2 (including)
Wireshark Wireshark 1.2.0 (including) 1.2.0 (including)
Wireshark Wireshark 1.2.1 (including) 1.2.1 (including)
Wireshark Wireshark 1.2.2 (including) 1.2.2 (including)
Wireshark Wireshark 1.2.3 (including) 1.2.3 (including)
Wireshark Wireshark 1.2.4 (including) 1.2.4 (including)
Wireshark Ubuntu hardy *
Wireshark Ubuntu intrepid *
Wireshark Ubuntu jaunty *
Wireshark Ubuntu karmic *
Wireshark Ubuntu upstream *
Red Hat Enterprise Linux 3 RedHat wireshark-0:1.0.11-EL3.6 *
Red Hat Enterprise Linux 4 RedHat wireshark-0:1.0.11-1.el4_8.5 *
Red Hat Enterprise Linux 5 RedHat wireshark-0:1.0.11-1.el5_5.5 *

References