CVE-2011-1590

The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wireshark:wireshark:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.8:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.9:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.12:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.13:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.14:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.2.15:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:wireshark:wireshark:1.4.4:*:*:*:*:*:*:*

History

13 Feb 2023, 04:29

Type Values Removed Values Added
Summary CVE-2011-1590 Wireshark: Use-after-free causes heap-based buffer overflow in X.509if dissector The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2011-1590', 'name': 'https://access.redhat.com/security/cve/CVE-2011-1590', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=697741', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=697741', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2012:0509', 'name': 'https://access.redhat.com/errata/RHSA-2012:0509', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 17:17

Type Values Removed Values Added
Summary The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file. CVE-2011-1590 Wireshark: Use-after-free causes heap-based buffer overflow in X.509if dissector
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2011-1590 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=697741 -
  • (MISC) https://access.redhat.com/errata/RHSA-2012:0509 -

Information

Published : 2011-04-29 22:55

Updated : 2023-12-10 11:03


NVD link : CVE-2011-1590

Mitre link : CVE-2011-1590

CVE.ORG link : CVE-2011-1590


JSON object : View

Products Affected

wireshark

  • wireshark
CWE
CWE-399

Resource Management Errors