First published: Tue May 11 2010(Updated: )
The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark | =0.99.8 | |
Ethereal | =0.9.6 | |
Wireshark | =0.99.3 | |
Wireshark | =0.99.0 | |
Wireshark | =1.0.9 | |
Wireshark | =1.0.1 | |
Ethereal | =0.99.0 | |
Ethereal | =0.9.8 | |
Wireshark | =0.9.6 | |
Wireshark | =0.99.6 | |
Wireshark | =1.0.2 | |
Wireshark | =0.99.2 | |
Wireshark | =0.99.1 | |
Wireshark | =1.0.4 | |
Wireshark | =1.0.3 | |
Wireshark | =1.0.6 | |
Wireshark | =1.0.10 | |
Wireshark | =1.0.12 | |
Wireshark | =1.0.8 | |
Wireshark | =1.0.5 | |
Wireshark | =0.99.5 | |
Ethereal | =0.9.7 | |
Wireshark | =0.99.4 | |
Wireshark | =1.0.0 | |
Wireshark | =1.0.11 | |
Wireshark | =0.99.7 | |
Wireshark | =1.0.7 | |
Wireshark | =1.2.7 | |
Wireshark | =1.2.6 | |
Wireshark | =1.2.0 | |
Wireshark | =1.2.3 | |
Wireshark | =1.2.5 | |
Wireshark | =1.2.1 | |
Wireshark | =1.2.4 | |
Wireshark | =1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1455 has a severity rating that qualifies it as having a potential for denial of service through application crashes.
To fix CVE-2010-1455, update to a version of Wireshark or Ethereal that is not affected, specifically any version later than 1.2.7.
CVE-2010-1455 is a vulnerability in the DOCSIS dissector of Wireshark that allows remote attackers to cause an application crash via a malformed packet trace.
CVE-2010-1455 affects Wireshark versions 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7, as well as certain versions of Ethereal.
Yes, CVE-2010-1455 can be exploited by remote attackers who assist in triggering the vulnerability through specific malformed packet traces.