VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2287
wireshark: Buffer overflow in the SigComp Universal Decompress...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2287

Original

Buffer overflow in the SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.8 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack vectors.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-15
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-15




Affected Product Tags
cpe:/a:wireshark:wireshark:0.10.10
cpe:/a:wireshark:wireshark:0.10.11
cpe:/a:wireshark:wireshark:0.10.12
cpe:/a:wireshark:wireshark:0.10.13
cpe:/a:wireshark:wireshark:0.10.14
cpe:/a:wireshark:wireshark:0.10.8
cpe:/a:wireshark:wireshark:0.10.9
cpe:/a:wireshark:wireshark:0.99.0
cpe:/a:wireshark:wireshark:0.99.1
cpe:/a:wireshark:wireshark:0.99.2
cpe:/a:wireshark:wireshark:0.99.3
cpe:/a:wireshark:wireshark:0.99.4
cpe:/a:wireshark:wireshark:0.99.5
cpe:/a:wireshark:wireshark:0.99.6
cpe:/a:wireshark:wireshark:0.99.7
cpe:/a:wireshark:wireshark:0.99.8
cpe:/a:wireshark:wireshark:1.0.0
cpe:/a:wireshark:wireshark:1.0.1
cpe:/a:wireshark:wireshark:1.0.10
cpe:/a:wireshark:wireshark:1.0.11
cpe:/a:wireshark:wireshark:1.0.12
cpe:/a:wireshark:wireshark:1.0.13
cpe:/a:wireshark:wireshark:1.0.2
cpe:/a:wireshark:wireshark:1.0.3
cpe:/a:wireshark:wireshark:1.0.4
cpe:/a:wireshark:wireshark:1.0.5
cpe:/a:wireshark:wireshark:1.0.6
cpe:/a:wireshark:wireshark:1.0.7
cpe:/a:wireshark:wireshark:1.0.8
cpe:/a:wireshark:wireshark:1.0.9
cpe:/a:wireshark:wireshark:1.2.0
cpe:/a:wireshark:wireshark:1.2.1
cpe:/a:wireshark:wireshark:1.2.2
cpe:/a:wireshark:wireshark:1.2.3
cpe:/a:wireshark:wireshark:1.2.4
cpe:/a:wireshark:wireshark:1.2.5
cpe:/a:wireshark:wireshark:1.2.6
cpe:/a:wireshark:wireshark:1.2.7
cpe:/a:wireshark:wireshark:1.2.8
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
CONFIRM http://www.wireshark.org/security/wnpa-sec-2010-06.html




CONFIRM http://www.wireshark.org/security/wnpa-sec-2010-05.html




MANDRIVA MDVSA-2010:113




MLIST [oss-security] 20100610 CVE request for new wireshark vulnerabilities




SECUNIA 40112




VUPEN ADV-2010-1418




Vulnerability Type Buffer Errors (CWE-119)





Copyright © 2010 JPCERT/CC All Rights Reserved.