CVE-2009-1210: Critical severity Wireshark Wireshark vulnerability
Published Apr 1, 2009
·Updated
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.
Affected Software
42 affected components
Wireshark Wireshark<=1.0.5
Wireshark Wireshark=0.6
Wireshark Wireshark=0.7.9
Wireshark Wireshark=0.8.16
Wireshark Wireshark=0.8.19
Wireshark Wireshark=0.9.5
Wireshark Wireshark=0.9.7
Wireshark Wireshark=0.9.8
Wireshark Wireshark=0.9.10
Wireshark Wireshark=0.9.14
Wireshark Wireshark=0.10
Wireshark Wireshark=0.10.1
Wireshark Wireshark=0.10.2
Wireshark Wireshark=0.10.3
Wireshark Wireshark=0.10.4
Wireshark Wireshark=0.10.5
Wireshark Wireshark=0.10.6
Wireshark Wireshark=0.10.7
Wireshark Wireshark=0.10.8
Wireshark Wireshark=0.10.9
Wireshark Wireshark=0.10.10
Wireshark Wireshark=0.10.11
Wireshark Wireshark=0.10.12
Wireshark Wireshark=0.10.13
Wireshark Wireshark=0.10.14
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.0
Wireshark Wireshark=0.99.1
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.4
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.6
Wireshark Wireshark=0.99.6a
Wireshark Wireshark=0.99.7
Wireshark Wireshark=0.99.8
Wireshark Wireshark=1.0
Wireshark Wireshark=1.0.0
Wireshark Wireshark=1.0.1
Wireshark Wireshark=1.0.2
Wireshark Wireshark=1.0.3
Wireshark Wireshark=1.0.4
Event History
Apr 1, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-1210?
CVE-2009-1210 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2009-1210?
To fix CVE-2009-1210, upgrade to Wireshark version 1.0.7 or later.
3
Which versions of Wireshark are affected by CVE-2009-1210?
CVE-2009-1210 affects Wireshark versions 1.0.6 and earlier, including versions down to 0.6.
4
What type of vulnerability is CVE-2009-1210?
CVE-2009-1210 is a format string vulnerability found in the PROFINET/DCP dissector of Wireshark.
5
Can CVE-2009-1210 be exploited remotely?
Yes, CVE-2009-1210 can be exploited remotely through specially crafted PN-DCP packets.