PT-2011-2898 · Wireshark+1 · Wireshark+1

Published

2011-03-02

·

Updated

2024-06-15

·

CVE-2011-1139

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.2.0 through 1.2.14 Wireshark versions 1.4.0 through 1.4.3
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This can be achieved by providing a pcap-ng file that contains a large packet-length field.
Recommendations For versions 1.2.0 through 1.2.14, update to a version outside of this range to resolve the issue. For versions 1.4.0 through 1.4.3, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of wiretap/pcapng.c until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1139
DSA-2201-1
OPENSUSE-SU-2024:10199-1
RHSA-2011:0369
RHSA-2011:0370
RHSA-2011_0369
RHSA-2011_0370

Affected Products

Red Hat
Wireshark