CVE-2009-0601: Low severity Wireshark Wireshark vulnerability
Published Feb 16, 2009
·Updated
Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.
Affected Software
23 affected components
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0.0
Wireshark Wireshark=1.0.1
Wireshark Wireshark=1.0.2
Wireshark Wireshark=1.0.3
Wireshark Wireshark=1.0.4
Wireshark Wireshark=1.0.5
Apple iOS and macOS
FreeBSD FreeBSD
Linux Linux
NetBSD NetBSD
Sun Solaris
All of the following
Any of the following
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0.0
Wireshark Wireshark=1.0.1
Wireshark Wireshark=1.0.2
Wireshark Wireshark=1.0.3
Wireshark Wireshark=1.0.4
Wireshark Wireshark=1.0.5
Any of the following
FreeBSD FreeBSD
Linux Linux kernel
NetBSD NetBSD
Sun Solaris
Remediation
Patch Available
Event History
Feb 16, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·08:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0601?
CVE-2009-0601 is classified as a denial of service vulnerability that can result in application crashes.
2
How do I fix CVE-2009-0601?
To fix CVE-2009-0601, upgrade Wireshark to version 1.0.6 or later.
3
Which versions of Wireshark are affected by CVE-2009-0601?
CVE-2009-0601 affects Wireshark versions 0.99.8 through 1.0.5 on non-Windows platforms.
4
What causes the CVE-2009-0601 vulnerability?
CVE-2009-0601 is caused by format string specifiers in the HOME environment variable.
5
Is there any mitigation available for CVE-2009-0601?
The best mitigation for CVE-2009-0601 is to ensure users do not set malicious values in the HOME environment variable.