CVE-2010-4300
EPSS 10.2%
Description
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.
How to fix CVE-2010-4300
To remediate CVE-2010-4300, upgrade the affected package to a fixed version below.
- Debian/wireshark—upgrade to 1.2.11-4 or later
Is CVE-2010-4300 being exploited?
Moderate — EPSS is 10.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.2.11-4