Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.
CVSS Details
- CVSS 3.1 Base Score: 6.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Feb 16, 2009 |
| Freebsd | — | Upgrade tethereal-liteUpgrade wiresharkUpgrade etherealUpgrade ethereal-liteUpgrade tetherealUpgrade wireshark-lite | Dec 10, 2025 | Mar 22, 2009 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Feb 16, 2009 |
| Suse | — | Upgrade wireshark-develUpgrade wireshark | Feb 17, 2015 | Feb 16, 2009 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Feb 16, 2009 |
| Wireshark | — | Upgrade to Wireshark version 1.0.6 | May 3, 2018 | Feb 16, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub