CVE-2009-1268: Input Validation
Published Apr 13, 2009
·Updated
The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHAMYSTATE packet.
Affected Software
22 affected components
Wireshark Wireshark=0.99.8
Wireshark Wireshark=0.99.3
Wireshark Wireshark=0.99.0
Wireshark Wireshark=1.0.1
Wireshark Wireshark=0.9.8
Wireshark Wireshark=1.0
Wireshark Wireshark=0.9.6
Wireshark Wireshark=0.99.6
Wireshark Wireshark=1.0.2
Wireshark Wireshark=0.99.2
Wireshark Wireshark=0.99.1
Wireshark Wireshark=1.0.4
Wireshark Wireshark=1.0.3
Wireshark Wireshark=1.0.6
Wireshark Wireshark=1.0.5
Wireshark Wireshark=0.99.5
Wireshark Wireshark=0.99.4
Wireshark Wireshark=1.0.0
Wireshark Wireshark=0.99.6a
Wireshark Wireshark=0.99
Wireshark Wireshark=0.99.7
Wireshark Wireshark=0.9.7
Event History
Apr 13, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1268?
CVE-2009-1268 is classified as a high severity vulnerability due to its potential to cause remote denial of service.
2
How do I fix CVE-2009-1268?
To fix CVE-2009-1268, upgrade Wireshark to a version later than 1.0.6 that addresses this vulnerability.
3
What versions of Wireshark are affected by CVE-2009-1268?
CVE-2009-1268 affects Wireshark versions 0.9.6 through 1.0.6.
4
What type of attack does CVE-2009-1268 involve?
CVE-2009-1268 involves a denial of service attack that can crash the Wireshark application.
5
Can CVE-2009-1268 be exploited remotely?
Yes, CVE-2009-1268 can be exploited remotely via crafted FWHA_MY_STATE packets.