Sploitus

CVE-2009-1210

2 known exploits for CVE-2009-1210

Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.

Affected products
Red Hat, Wireshark
Wireshark
≤ 1.0.5, 0.6, 0.7.9, 0.8.16, 0.8.19, 0.9.5, 0.9.7, 0.9.8, 0.9.10, 0.9.14, 0.10, 0.10.1, 0.10.2, 0.10.3, 0.10.4, 0.10.5, 0.10.6, 0.10.7, 0.10.8, 0.10.9, 0.10.10, 0.10.11, 0.10.12, 0.10.13, 0.10.14, 0.99, 0.99.0, 0.99.1, 0.99.2, 0.99.3, 0.99.4, 0.99.5, 0.99.6, 0.99.6a, 0.99.7, 0.99.8, 1.0, 1.0.0, 1.0.1, 1.0.2
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
15.2% (97th percentile)
Weakness
CWE-134
NVD status
Modified
Published
2009-04-01
CVE-2009-1210 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2009-1210

Proof-of-concept code and exploit modules indexed by Sploitus