CVE-2009-1210

Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
wiresharkwireshark
𝑥
≤ 1.0.5
wiresharkwireshark
0.6
wiresharkwireshark
0.7.9
wiresharkwireshark
0.8.16
wiresharkwireshark
0.8.19
wiresharkwireshark
0.9.5
wiresharkwireshark
0.9.7
wiresharkwireshark
0.9.8
wiresharkwireshark
0.9.10
wiresharkwireshark
0.9.14
wiresharkwireshark
0.10
wiresharkwireshark
0.10.1
wiresharkwireshark
0.10.2
wiresharkwireshark
0.10.3
wiresharkwireshark
0.10.4
wiresharkwireshark
0.10.5
wiresharkwireshark
0.10.6
wiresharkwireshark
0.10.7
wiresharkwireshark
0.10.8
wiresharkwireshark
0.10.9
wiresharkwireshark
0.10.10
wiresharkwireshark
0.10.11
wiresharkwireshark
0.10.12
wiresharkwireshark
0.10.13
wiresharkwireshark
0.10.14
wiresharkwireshark
0.99
wiresharkwireshark
0.99.0
wiresharkwireshark
0.99.1
wiresharkwireshark
0.99.2
wiresharkwireshark
0.99.3
wiresharkwireshark
0.99.4
wiresharkwireshark
0.99.5
wiresharkwireshark
0.99.6
wiresharkwireshark
0.99.6a:a
wiresharkwireshark
0.99.7
wiresharkwireshark
0.99.8
wiresharkwireshark
1.0
wiresharkwireshark
1.0.0
wiresharkwireshark
1.0.1
wiresharkwireshark
1.0.2
wiresharkwireshark
1.0.3
wiresharkwireshark
1.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wireshark
bookworm
4.0.11-1~deb12u1
fixed
bookworm (security)
4.0.11-1~deb12u1
fixed
bullseye
3.4.10-0+deb11u1
fixed
bullseye (security)
3.4.16-0+deb11u1
fixed
etch
not-affected
sid
4.4.1-1
fixed
trixie
4.4.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wireshark
dapper
dne
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libwireshark9
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 15
2.4.6-1.31
fixed
libwiretap7
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 15
2.4.6-1.31
fixed
libwscodecs1
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 15
2.4.6-1.31
fixed
libwsutil8
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 15
2.4.6-1.31
fixed
wireshark
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 15
2.4.6-1.31
fixed
wireshark-devel
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 15
2.4.6-1.31
fixed
wireshark-gtk
suse enterprise sap 12 SP5
2.4.16-48.51.1
fixed
suse enterprise server 12 SP5
2.4.16-48.51.1
fixed
wireshark-ui-qt
suse enterprise desktop 15
2.4.6-1.31
fixed
suse enterprise sap 15
2.4.6-1.31
fixed
suse enterprise server 15
2.4.6-1.31
fixed
References