CVE-2009-1210

Severity CVSS v4.0:
Pending analysis
Type:
CWE-134 Format String Vulnerability
Publication date:
01/04/2009
Last modified:
09/04/2025

Description

Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wireshark:wireshark:*:*:*:*:*:*:*:* 1.0.5 (including)
cpe:2.3:a:wireshark:wireshark:0.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.7.9:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.8.16:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.8.19:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.9.14:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:0.10.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools