Unrated severityNVD Advisory· Published Feb 3, 2010· Updated Apr 29, 2026
CVE-2010-0304
CVE-2010-0304
Description
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
Affected products
20cpe:2.3:a:wireshark:wireshark:0.9.15:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:wireshark:wireshark:0.9.15:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:wireshark:wireshark:1.2.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- www.vupen.com/english/advisories/2010/0239nvdPatchVendor Advisory
- www.securityfocus.com/bid/37985nvdExploit
- secunia.com/advisories/38257nvdVendor Advisory
- secunia.com/advisories/38348nvdVendor Advisory
- www.wireshark.org/security/wnpa-sec-2010-02.htmlnvdVendor Advisory
- anonsvn.wireshark.org/viewvc/trunk-1.2/epan/dissectors/packet-lwres.cnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-March/036415.htmlnvd
- osvdb.org/61987nvd
- secunia.com/advisories/38829nvd
- www.debian.org/security/2010/dsa-1983nvd
- www.mandriva.com/security/advisoriesnvd
- www.metasploit.com/modules/exploit/multi/misc/wireshark_lwres_getaddrbynamenvd
- www.openwall.com/lists/oss-security/2010/01/29/4nvd
- www.securitytracker.com/idnvd
- www.wireshark.org/security/wnpa-sec-2010-01.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/55951nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8490nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9933nvd
News mentions
0No linked articles in our index yet.