Candidate: CVE-2009-4377 PublicDate: 2009-12-21 21:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4377 http://www.wireshark.org/security/wnpa-sec-2009-09.html Description: The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_wireshark: upstream_wireshark: released (1.0.11, 1.2.5) dapper_wireshark: DNE hardy_wireshark: ignored (reached end-of-life) intrepid_wireshark: needed (reached end-of-life) jaunty_wireshark: ignored (reached end-of-life) karmic_wireshark: ignored (reached end-of-life) lucid_wireshark: not-affected (1.2.7-1) maverick_wireshark: not-affected (1.2.7-1) natty_wireshark: not-affected (1.2.7-1) oneiric_wireshark: not-affected (1.2.7-1) devel_wireshark: not-affected (1.2.7-1)