vendor:
Wireshark
by:
Unknown
5.5
CVSS
MEDIUM
Denial-of-Service
20
CWE
Product Name: Wireshark
Affected Version From: 1.4.2000
Affected Version To: 1.6.2001
Patch Exists: YES
Related CWE: CVE-2011-1590
CPE: a:wireshark:wireshark
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0509/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-1590/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-1590/, https://www.rapid7.com/db/vulnerabilities/wireshark-cve-2011-1590/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-1590/
Platforms Tested:
2011
Remote Denial-of-Service Vulnerability in Wireshark
Wireshark is prone to a remote denial-of-service vulnerability because it fails to properly handle certain files. Successful exploits may allow attackers to crash the affected application, denying service to legitimate users.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version of the software.