CVE-2011-0445: Medium severity wireshark vulnerability
Published Jan 12, 2011
·Updated
The ASN.1 BER dissector in Wireshark 1.4.0 through 1.4.2 allows remote attackers to cause a denial of service (assertion failure) via crafted packets, as demonstrated by fuzz-2010-12-30-28473.pcap.
Affected Software
3 affected components
Wireshark Wireshark=1.4.0
Wireshark Wireshark=1.4.1
Wireshark Wireshark=1.4.2
Event History
Jan 12, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0445?
CVE-2011-0445 has a severity rating that indicates it can cause a denial of service in affected versions of Wireshark.
2
How do I fix CVE-2011-0445?
To fix CVE-2011-0445, upgrade to Wireshark version 1.4.3 or later.
3
Which versions of Wireshark are affected by CVE-2011-0445?
Wireshark versions 1.4.0 through 1.4.2 are affected by CVE-2011-0445.
4
What type of attack can exploit CVE-2011-0445?
CVE-2011-0445 can be exploited by remote attackers via crafted ASN.1 BER packets.
5
What happens when CVE-2011-0445 is exploited?
Exploiting CVE-2011-0445 can lead to assertion failures and result in a denial of service.