CVE-2010-1455: Input Validation
The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1455?
CVE-2010-1455 has a severity rating that qualifies it as having a potential for denial of service through application crashes.
How do I fix CVE-2010-1455?
To fix CVE-2010-1455, update to a version of Wireshark or Ethereal that is not affected, specifically any version later than 1.2.7.
What is CVE-2010-1455?
CVE-2010-1455 is a vulnerability in the DOCSIS dissector of Wireshark that allows remote attackers to cause an application crash via a malformed packet trace.
Which versions are affected by CVE-2010-1455?
CVE-2010-1455 affects Wireshark versions 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7, as well as certain versions of Ethereal.
Can CVE-2010-1455 be exploited remotely?
Yes, CVE-2010-1455 can be exploited by remote attackers who assist in triggering the vulnerability through specific malformed packet traces.