CVE-2011-0024: Buffer Overflow
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
Other sources
Marc Schoenefeld found a heap-based buffer overflow in Wireshark, when reading certain capture files.
A remote attacker could use this flaw to cause wireshark executable to crash or, potentially, execute arbitrary code with the privileges of the user running wireshark, if the local user opened a specially-crafted capture file.
This only affects wireshark < 1.2
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0024?
CVE-2011-0024 has been classified as a critical vulnerability due to its potential to cause denial of service and possibly execute arbitrary code.
How do I fix CVE-2011-0024?
To fix CVE-2011-0024, update Wireshark to the latest version that addresses this vulnerability.
Which versions of Wireshark are affected by CVE-2011-0024?
CVE-2011-0024 affects multiple versions of Wireshark, including versions up to 1.0.16 and specific earlier versions.
What could happen if CVE-2011-0024 is exploited?
If exploited, CVE-2011-0024 could lead to application crashes and potentially allow attackers to execute arbitrary code.
Is there a workaround for CVE-2011-0024?
There is no known workaround for CVE-2011-0024; the recommended action is to update to a patched version of Wireshark.