CVE-2009-3829: Integer Overflow
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3829?
CVE-2009-3829 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code or cause a denial of service.
How do I fix CVE-2009-3829?
To fix CVE-2009-3829, upgrade to Wireshark version 1.2.2 or later.
What versions of Wireshark are affected by CVE-2009-3829?
CVE-2009-3829 affects Wireshark versions prior to 1.2.2, including 0.99.x and 1.0.x versions.
What types of attacks can exploit CVE-2009-3829?
CVE-2009-3829 can be exploited through crafted erf files which can lead to arbitrary code execution or application crashes.
Is there a workaround for CVE-2009-3829 if I cannot upgrade?
There are no documented workarounds for CVE-2009-3829, so upgrading is the recommended solution.