Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-gnomeUpgrade wireshark | Dec 1, 2016 | Apr 1, 2009 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Apr 1, 2009 |
| Freebsd | — | Upgrade tetherealUpgrade wiresharkUpgrade tethereal-liteUpgrade ethereal-liteUpgrade etherealUpgrade wireshark-lite | Dec 10, 2025 | May 9, 2009 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Apr 1, 2009 |
| Oracle_linux | — | Upgrade wireshark-gnomeUpgrade wireshark | Oct 16, 2024 | Apr 1, 2009 |
| Suse | — | Upgrade libwsutil17Upgrade wireshark-ui-qtUpgrade libwsutil7Upgrade libwiretap7Upgrade libwiretap6Upgrade wireshark-gtkUpgrade libwsutil8Upgrade libwireshark9Upgrade libwsutil16Upgrade libwireshark19Upgrade wireshark-develUpgrade libwiretap15Upgrade libwscodecs1Upgrade libwireshark8Upgrade wiresharkUpgrade libwireshark18Upgrade libwiretap16 | Feb 17, 2015 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 1.0.7 | Oct 4, 2017 | Apr 1, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub