CVE-2009-4376: Buffer Overflow
Published Dec 21, 2009
·Updated
Buffer overflow in the daintreesnaread function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Affected Software
5 affected components
Wireshark Wireshark=1.2.0
Wireshark Wireshark=1.2.1
Wireshark Wireshark=1.2.2
Wireshark Wireshark=1.2.3
Wireshark Wireshark=1.2.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 21, 2009
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4376?
CVE-2009-4376 has a high severity due to its potential to cause a denial of service and execute arbitrary code.
2
How do I fix CVE-2009-4376?
To fix CVE-2009-4376, upgrade Wireshark to a version later than 1.2.4.
3
What versions of Wireshark are affected by CVE-2009-4376?
Wireshark versions 1.2.0 through 1.2.4 are affected by CVE-2009-4376.
4
What type of vulnerability is CVE-2009-4376?
CVE-2009-4376 is a buffer overflow vulnerability in the Daintree SNA file parser.
5
Can CVE-2009-4376 lead to remote code execution?
Yes, CVE-2009-4376 can allow remote attackers to execute arbitrary code through crafted packets.