Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-4101

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-4101
Last Modified 13 Aug 2012 11:31:25
Published 03 Nov 2011 11:55:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-4101

Summary

The dissect_infiniband_common function in epan/dissectors/packet-infiniband.c in the Infiniband dissector in Wireshark 1.4.0 through 1.4.9 and 1.6.x before 1.6.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed packet.

Vulnerable Systems

Application

  • Wireshark 1.4.0

  • Wireshark 1.4.1

  • Wireshark 1.4.2

  • Wireshark 1.4.3

  • Wireshark 1.4.4

  • Wireshark 1.4.5

  • Wireshark 1.4.6

  • Wireshark 1.4.7

  • Wireshark 1.4.8

  • Wireshark 1.4.9

  • Wireshark 1.6.0

  • Wireshark 1.6.1

  • Wireshark 1.6.2


References

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=750645

CONFIRM - http://anonsvn.wireshark.org/viewvc?view=revision&revision=39500

CONFIRM - https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=6476

CONFIRM - http://www.wireshark.org/security/wnpa-sec-2011-18.html

MLIST - [oss-security] 20111101 Re: CVE request for wireshark flaws

XF - wireshark-infiniband-dissector-dos(71091)

BID - 50481

SECUNIA - 46644

OSVDB - 76769


Last Updated: 27 May 2016 10:58:06