CVE-2011-1959
wireshark: Stack-based buffer over-read from tvbuff buffer when reading snoop capture files
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The snoop_read function in wiretap/snoop.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 does not properly handle certain virtualizable buffers, which allows remote attackers to cause a denial of service (application crash) via a large length value in a snoop file that triggers a stack-based buffer over-read.
La función snoop_read en wiretap/snoop.c de Wireshark v1.2.x antes de v1.2.17 y v1.4.x antes de v1.4.7 no maneja adecuadamente ciertos búfers virtualizables, que permite a atacantes remotos provocar una denegación de servicio ( caída de aplicación) a través de un valor de longitud grande en un archivo de Snoop que desencadena un búfer una sobre-lectura en la pila del búfer.
Wireshark, previously known as Ethereal, is a network protocol analyzer. It is used to capture and browse the traffic running on a computer network. A heap-based buffer overflow flaw was found in the way Wireshark handled Endace ERF capture files. If Wireshark opened a specially-crafted ERF capture file, it could crash or, possibly, execute arbitrary code as the user running Wireshark. Several denial of service flaws were found in Wireshark. Wireshark could crash or stop responding if it read a malformed packet off a network, or opened a malicious dump file.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-05-09 CVE Reserved
- 2011-06-06 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-04-02 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (21)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2011/05/31/20 | Mailing List | |
http://openwall.com/lists/oss-security/2011/06/01/1 | Mailing List | |
http://openwall.com/lists/oss-security/2011/06/01/11 | Mailing List | |
http://secunia.com/advisories/44449 | Third Party Advisory | |
http://secunia.com/advisories/44958 | Third Party Advisory | |
http://secunia.com/advisories/45149 | Third Party Advisory | |
http://secunia.com/advisories/48947 | Third Party Advisory | |
http://www.securityfocus.com/bid/48066 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/67792 | Vdb Entry | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14656 | Signature |
URL | Date | SRC |
---|---|---|
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5912 | 2024-08-06 | |
https://bugzilla.redhat.com/show_bug.cgi?id=710039 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://anonsvn.wireshark.org/viewvc?view=revision&revision=37068 | 2017-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2 Search vendor "Wireshark" for product "Wireshark" and version "1.2" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.0 Search vendor "Wireshark" for product "Wireshark" and version "1.2.0" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.1 Search vendor "Wireshark" for product "Wireshark" and version "1.2.1" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.2 Search vendor "Wireshark" for product "Wireshark" and version "1.2.2" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.3 Search vendor "Wireshark" for product "Wireshark" and version "1.2.3" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.4 Search vendor "Wireshark" for product "Wireshark" and version "1.2.4" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.5 Search vendor "Wireshark" for product "Wireshark" and version "1.2.5" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.6 Search vendor "Wireshark" for product "Wireshark" and version "1.2.6" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.7 Search vendor "Wireshark" for product "Wireshark" and version "1.2.7" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.8 Search vendor "Wireshark" for product "Wireshark" and version "1.2.8" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.9 Search vendor "Wireshark" for product "Wireshark" and version "1.2.9" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.10 Search vendor "Wireshark" for product "Wireshark" and version "1.2.10" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.11 Search vendor "Wireshark" for product "Wireshark" and version "1.2.11" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.12 Search vendor "Wireshark" for product "Wireshark" and version "1.2.12" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.13 Search vendor "Wireshark" for product "Wireshark" and version "1.2.13" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.14 Search vendor "Wireshark" for product "Wireshark" and version "1.2.14" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.15 Search vendor "Wireshark" for product "Wireshark" and version "1.2.15" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.2.16 Search vendor "Wireshark" for product "Wireshark" and version "1.2.16" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.0 Search vendor "Wireshark" for product "Wireshark" and version "1.4.0" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.1 Search vendor "Wireshark" for product "Wireshark" and version "1.4.1" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.2 Search vendor "Wireshark" for product "Wireshark" and version "1.4.2" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.3 Search vendor "Wireshark" for product "Wireshark" and version "1.4.3" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.4 Search vendor "Wireshark" for product "Wireshark" and version "1.4.4" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.5 Search vendor "Wireshark" for product "Wireshark" and version "1.4.5" | - |
Affected
| ||||||
Wireshark Search vendor "Wireshark" | Wireshark Search vendor "Wireshark" for product "Wireshark" | 1.4.6 Search vendor "Wireshark" for product "Wireshark" and version "1.4.6" | - |
Affected
|