PT-2011-2578 · Wireshark+1 · Wireshark+1
Published
2011-03-02
·
Updated
2024-06-15
·
CVE-2011-0713
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Wireshark versions 1.2.0 through 1.2.14
Wireshark versions 1.4.0 through 1.4.3
Description
A heap-based buffer overflow issue exists, allowing remote attackers to cause a denial of service, potentially leading to an application crash, or possibly having other unspecified impacts. This occurs via a long record in a Nokia DCT3 trace file.
Recommendations
For Wireshark versions 1.2.0 through 1.2.14, update to a version outside of this range to resolve the issue.
For Wireshark versions 1.4.0 through 1.4.3, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider avoiding the use of Nokia DCT3 trace files with long records until a patch is available.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Wireshark