Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade wireshark-gnomeUpgrade wireshark | Dec 1, 2016 | Jul 21, 2009 |
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Jul 21, 2009 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Jul 21, 2009 |
| Oracle_linux | — | Upgrade wiresharkUpgrade wireshark-gnome | Oct 16, 2024 | Jul 21, 2009 |
| Suse | — | Upgrade wiresharkUpgrade wireshark-devel | Feb 17, 2015 | Jun 28, 2013 |
| Wireshark | — | Upgrade to Wireshark version 1.2.1 | Oct 4, 2017 | Jul 21, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub