Candidate: CVE-2009-0601 PublicDate: 2009-02-16 20:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0601 Description: Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_wireshark: upstream_wireshark: released (1.0.6) dapper_wireshark: DNE gutsy_wireshark: needed (reached end-of-life) hardy_wireshark: ignored (reached end-of-life) intrepid_wireshark: needed (reached end-of-life) jaunty_wireshark: released (1.0.6-1ubuntu1) karmic_wireshark: released (1.0.6-1ubuntu1) lucid_wireshark: released (1.0.6-1ubuntu1) maverick_wireshark: released (1.0.6-1ubuntu1) natty_wireshark: released (1.0.6-1ubuntu1) oneiric_wireshark: released (1.0.6-1ubuntu1) devel_wireshark: released (1.0.6-1ubuntu1)