Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2995

Опубликовано: 09 июн. 2010
Источник: redhat
CVSS2: 5.4
EPSS Низкий

Описание

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wiresharkNot affected
Red Hat Enterprise Linux 3wiresharkFixedRHSA-2010:062511.08.2010
Red Hat Enterprise Linux 4wiresharkFixedRHSA-2010:062511.08.2010
Red Hat Enterprise Linux 5wiresharkFixedRHSA-2010:062511.08.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=604308wireshark: SigComp UDVM dissector buffer overruns

EPSS

Процентиль: 91%
0.06637
Низкий

5.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

nvd
почти 15 лет назад

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

debian
почти 15 лет назад

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark ...

github
около 3 лет назад

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 through 1.0.14 and 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

oracle-oval
почти 15 лет назад

ELSA-2010-0625: wireshark security update (MODERATE)

EPSS

Процентиль: 91%
0.06637
Низкий

5.4 Medium

CVSS2