← back
CVE-2010-0304

CVE-2010-0304

60Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 74%
from disclosure to weapon0 days
Published on NVDFeb 3
1st PoCJan 29
metasploitJan 27
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
11 products (200 components)
Red Hat Desktop version 3 · Red Hat Enterprise Linux AS version 3 · Red Hat Enterprise Linux AS version 4 · Red Hat Enterprise Linux Desktop version 4 · Red Hat Enterprise Linux ES version 3 · and others 6
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.