FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-0601

This CVE name corresponds to:

Entered Topic
2009-03-22 wireshark -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-0601
Phase Assigned(20090216)

Description

Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.

References

Source Reference
BUGTRAQ 20090312 rPSA-2009-0040-1 tshark wireshark
CONFIRM http://www.wireshark.org/security/wnpa-sec-2009-01.html
CONFIRM https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3150
CONFIRM http://wiki.rpath.com/Advisories:rPSA-2009-0040
CONFIRM https://issues.rpath.com/browse/RPL-2984
SUSE SUSE-SR:2009:005
BID 33690
SECUNIA 34264
VUPEN ADV-2009-0370
SECTRACK 1021697