CVE-2009-1210

Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
http://secunia.com/advisories/34542 Vendor Advisory
http://secunia.com/advisories/34778 Vendor Advisory
http://secunia.com/advisories/34970 Vendor Advisory
http://secunia.com/advisories/35133 Vendor Advisory
http://secunia.com/advisories/35224 Vendor Advisory
http://secunia.com/advisories/35416 Vendor Advisory
http://secunia.com/advisories/35464 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0062
http://www.debian.org/security/2009/dsa-1785
http://www.mandriva.com/security/advisories?name=MDVSA-2009:088
http://www.redhat.com/support/errata/RHSA-2009-1100.html
http://www.securityfocus.com/archive/1/502745/100/0/threaded
http://www.securityfocus.com/bid/34291 Exploit
http://www.wireshark.org/security/wnpa-sec-2009-02.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5976
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9526
https://www.exploit-db.com/exploits/8308
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
http://secunia.com/advisories/34542 Vendor Advisory
http://secunia.com/advisories/34778 Vendor Advisory
http://secunia.com/advisories/34970 Vendor Advisory
http://secunia.com/advisories/35133 Vendor Advisory
http://secunia.com/advisories/35224 Vendor Advisory
http://secunia.com/advisories/35416 Vendor Advisory
http://secunia.com/advisories/35464 Vendor Advisory
http://wiki.rpath.com/Advisories:rPSA-2009-0062
http://www.debian.org/security/2009/dsa-1785
http://www.mandriva.com/security/advisories?name=MDVSA-2009:088
http://www.redhat.com/support/errata/RHSA-2009-1100.html
http://www.securityfocus.com/archive/1/502745/100/0/threaded
http://www.securityfocus.com/bid/34291 Exploit
http://www.wireshark.org/security/wnpa-sec-2009-02.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/49512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5976
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9526
https://www.exploit-db.com/exploits/8308
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.8.16:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.8.19:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.14:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.4:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.9:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.11:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.12:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.13:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.14:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.4:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.6a:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.99.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.0.4:*:*:*:*:*:*:*

History

21 Nov 2024, 01:01

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html -
References () http://secunia.com/advisories/34542 - Vendor Advisory () http://secunia.com/advisories/34542 - Vendor Advisory
References () http://secunia.com/advisories/34778 - Vendor Advisory () http://secunia.com/advisories/34778 - Vendor Advisory
References () http://secunia.com/advisories/34970 - Vendor Advisory () http://secunia.com/advisories/34970 - Vendor Advisory
References () http://secunia.com/advisories/35133 - Vendor Advisory () http://secunia.com/advisories/35133 - Vendor Advisory
References () http://secunia.com/advisories/35224 - Vendor Advisory () http://secunia.com/advisories/35224 - Vendor Advisory
References () http://secunia.com/advisories/35416 - Vendor Advisory () http://secunia.com/advisories/35416 - Vendor Advisory
References () http://secunia.com/advisories/35464 - Vendor Advisory () http://secunia.com/advisories/35464 - Vendor Advisory
References () http://wiki.rpath.com/Advisories:rPSA-2009-0062 - () http://wiki.rpath.com/Advisories:rPSA-2009-0062 -
References () http://www.debian.org/security/2009/dsa-1785 - () http://www.debian.org/security/2009/dsa-1785 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:088 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:088 -
References () http://www.redhat.com/support/errata/RHSA-2009-1100.html - () http://www.redhat.com/support/errata/RHSA-2009-1100.html -
References () http://www.securityfocus.com/archive/1/502745/100/0/threaded - () http://www.securityfocus.com/archive/1/502745/100/0/threaded -
References () http://www.securityfocus.com/bid/34291 - Exploit () http://www.securityfocus.com/bid/34291 - Exploit
References () http://www.wireshark.org/security/wnpa-sec-2009-02.html - Vendor Advisory () http://www.wireshark.org/security/wnpa-sec-2009-02.html - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49512 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49512 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5976 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5976 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9526 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9526 -
References () https://www.exploit-db.com/exploits/8308 - () https://www.exploit-db.com/exploits/8308 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html - () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html - () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html - () https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html -

Information

Published : 2009-04-01 10:30

Updated : 2024-11-21 01:01


NVD link : CVE-2009-1210

Mitre link : CVE-2009-1210

CVE.ORG link : CVE-2009-1210


JSON object : View

Products Affected

wireshark

  • wireshark
CWE
CWE-134

Use of Externally-Controlled Format String