10
CVSSv2

CVE-2010-2995

Published: 13/08/2010 Updated: 19/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The SigComp Universal Decompressor Virtual Machine (UDVM) in Wireshark 0.10.8 up to and including 1.0.14 and 1.2.0 up to and including 1.2.9 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to sigcomp-udvm.c and an off-by-one error, which triggers a buffer overflow, different vulnerabilities than CVE-2010-2287.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 1.2.9

wireshark wireshark 1.2.7

wireshark wireshark 1.2.1

wireshark wireshark 1.0.5

wireshark wireshark 1.0.7

wireshark wireshark 1.0.13

wireshark wireshark 1.0.14

wireshark wireshark 0.10.14

wireshark wireshark 1.2.5

wireshark wireshark 1.2.8

wireshark wireshark 1.0.12

wireshark wireshark 1.0.11

wireshark wireshark 1.0.9

wireshark wireshark 1.2.6

wireshark wireshark 1.0.1

wireshark wireshark 1.2.0

wireshark wireshark 0.10.9

wireshark wireshark 1.2.3

wireshark wireshark 0.10.8

wireshark wireshark 1.0.2

wireshark wireshark 1.0.4

wireshark wireshark 1.0.3

wireshark wireshark 1.0.6

wireshark wireshark 1.0.10

wireshark wireshark 0.10.13

wireshark wireshark 0.10.12

wireshark wireshark 0.10.10

wireshark wireshark 1.0.8

wireshark wireshark 1.2.4

wireshark wireshark 1.2

wireshark wireshark 0.10.11

wireshark wireshark 1.2.2

wireshark wireshark 1.0.0

Vendor Advisories

Synopsis Moderate: wireshark security update Type/Severity Security Advisory: Moderate Topic Updated wireshark packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 3, 4, and 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Commo ...
Several implementation errors in the dissector of the Wireshark network traffic analyzer for the ASN1 BER protocol and in the SigComp Universal Decompressor Virtual Machine may lead to the execution of arbitrary code For the stable distribution (lenny), these problems have been fixed in version 102-3+lenny10 For the unstable distribution (sid) ...