Vulnerability record · CVE-2010-0304 · published 3 February 2010
CVE-2010-0304: Wireshark LWRES dissector buffer overflow via malformed packet
Wireshark · Wireshark
The LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 contains multiple buffer overflows, including a stack-based overflow in dissect_getaddrsbyname_request. A malformed packet triggers the overflow, crashing the application and potentially allowing code execution.
Description
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityCVSS 7.5 and public exploit code with very high EPSS make this a serious risk for exposed Wireshark instances, though it is not known to be actively exploited in the wild.
What it is
The LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 contains multiple buffer overflows, including a stack-based overflow in dissect_getaddrsbyname_request. A malformed packet triggers the overflow, crashing the application and potentially allowing code execution.
Impact
A remote attacker can crash Wireshark and, given the stack-based overflow, may achieve arbitrary code execution in the context of the user running Wireshark.
Attack surface
Reached by a malformed LWRES packet processed by the dissector, either captured from the network or opened from a file. No authentication or user interaction beyond normal packet capture or file opening is required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.73666 (99.4th percentile) and a Metasploit module and SecurityFocus exploit reference exist, indicating public exploit code is available.
What to do
- Upgrade Wireshark to a version later than 1.0.10 or 1.2.5 that includes the LWRES dissector fix.
- Apply vendor patches from Wireshark, Debian, Fedora, Mandriva or other distributions as applicable.
- Disable the LWRES dissector if it is not needed for monitoring.
- Avoid opening untrusted packet capture files in Wireshark.
- Restrict network capture to trusted segments where possible.
Detection
- Monitor for Wireshark crashes or abnormal process termination when processing LWRES traffic.
- Inspect packet captures for malformed LWRES getaddrsbyname requests.
- Check endpoint logs for unexpected Wireshark process exits correlated with network activity.
- Use IDS signatures for LWRES buffer overflow attempts if available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-0304 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-0304), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.