CVE-2009-2560: Medium severity wireshark vulnerability
Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2560?
CVE-2009-2560 is considered a denial of service vulnerability that can cause an application crash.
How do I fix CVE-2009-2560?
To mitigate CVE-2009-2560, upgrade to a version of Wireshark that is not affected by this vulnerability.
What versions of Wireshark are affected by CVE-2009-2560?
CVE-2009-2560 affects Wireshark versions 1.0.0 to 1.2.0 and several incremental versions in between.
Can CVE-2009-2560 be exploited remotely?
Yes, CVE-2009-2560 can be exploited by remote attackers through specially crafted packet trace files.
What components of Wireshark are implicated in CVE-2009-2560?
CVE-2009-2560 affects the Bluetooth L2CAP, RADIUS, and MIOP dissectors.