Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2698

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-2698
Last Modified 06 Feb 2013 11:45:41
Published 23 Aug 2011 05:55:01
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-2698

Summary

Off-by-one error in the elem_cell_id_aux function in epan/dissectors/packet-ansi_a.c in the ANSI MAP dissector in Wireshark 1.4.x before 1.4.8 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (infinite loop) via an invalid packet.

Vulnerable Systems

Application

  • Wireshark 1.4.0

  • Wireshark 1.4.1

  • Wireshark 1.4.2

  • Wireshark 1.4.3

  • Wireshark 1.4.4

  • Wireshark 1.4.5

  • Wireshark 1.4.6

  • Wireshark 1.4.7

  • Wireshark 1.6.0


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=723215

MLIST - [oss-security] 20110720 Re: CVE Request -- Wireshark: Infinite loop in the ANSI A Interface (IS-634/IOS) dissector

MLIST - [oss-security] 20110719 CVE Request -- Wireshark: Infinite loop in the ANSI A Interface (IS-634/IOS) dissector

FEDORA - FEDORA-2011-9640

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=37930

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6044

XF - wireshark-ansiamap-dos(69074)

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2011-11.html

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2011-10.html

BID - 49071

SECUNIA - 45574

SECUNIA - 45086

FEDORA - FEDORA-2011-9638

SECUNIA - 48947

REDHAT - RHSA-2013:0125

Related Patches

Red Hat 2013:0125-01 RHSA Moderate: wireshark security, bug fix, and enhancement update for RHEL 5 x86

Novell SUSE 2011:5281 wireshark security update for SLE 11 SP1 i586

Novell SUSE 2011:7796 wireshark security update for SLE 10 SP4 i586


Last Updated: 27 May 2016 10:57:37