Resource management error in Wireshark - CVE-2011-1590

 

Resource management error in Wireshark - CVE-2011-1590

Published: April 30, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45101
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1590
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.


Affected software

Wireshark
Amazon Linux AMI

How to mitigate CVE-2011-1590

Install update from vendor's website.


External References

Related Security Bulletins