Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4100

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-4100
Last Modified 13 Aug 2012 11:31:25
Published 03 Nov 2011 11:55:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4100

Summary

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

Vulnerable Systems

Application

  • Wireshark 1.6.0

  • Wireshark 1.6.1

  • Wireshark 1.6.2


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=750643

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6351

MLIST - [oss-security] 20111101 Re: CVE request for wireshark flaws

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=39140

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2011-17.html

XF - wireshark-csn1-dissector-dos(71090)

BID - 50479

SECUNIA - 46644

OSVDB - 76768


Last Updated: 27 May 2016 10:58:06