CVE-2011-0538: Buffer Overflow

Published Feb 8, 2011
·
Updated

Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0538 to the following vulnerability:

Name: CVE-2011-0538 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0538 Assigned: 20110120 Reference: MLIST:[oss-security] 20110204 Wireshark: Freeing uninitialized pointer Reference: URL:http://openwall.com/lists/oss-security/2011/02/04/1 Reference: MISC:https://srcm.symantec.com/EditVulnerabilityFixes.aspx?docId=549474 Reference: CONFIRM:https://bugs.wireshark.org/bugzilla/showbug.cgi?id=5652 Reference: BID:46167 Reference: URL:http://www.securityfocus.com/bid/46167

Wireshark 1.5.0, 1.4.3, and earlier frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed file.

Other sources

Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed file.

MITRE

Affected Software

20 affected components
Wireshark Wireshark=1.2.0
Wireshark Wireshark=1.2.1
Wireshark Wireshark=1.2.2
Wireshark Wireshark=1.2.3
Wireshark Wireshark=1.2.4
Wireshark Wireshark=1.2.5
Wireshark Wireshark=1.2.6
Wireshark Wireshark=1.2.7
Wireshark Wireshark=1.2.8
Wireshark Wireshark=1.2.9
Wireshark Wireshark=1.2.10
Wireshark Wireshark=1.2.11
Wireshark Wireshark=1.2.12
Wireshark Wireshark=1.2.13
Wireshark Wireshark=1.2.14
Wireshark Wireshark=1.4.0
Wireshark Wireshark=1.4.1
Wireshark Wireshark=1.4.2
Wireshark Wireshark=1.4.3
Wireshark Wireshark=1.5.0

Event History

Feb 8, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Feb 9, 2011
Data Sourced
06:31 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2011-0538?

CVE-2011-0538 has been classified as high severity due to possible denial of service attacks.

2

What versions of Wireshark are affected by CVE-2011-0538?

CVE-2011-0538 affects Wireshark versions 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3.

3

How do I fix CVE-2011-0538?

The best way to fix CVE-2011-0538 is to upgrade Wireshark to a version later than 1.4.3 or 1.2.14.

4

What kind of vulnerability is CVE-2011-0538?

CVE-2011-0538 is a vulnerability that allows a remote attacker to trigger a denial of service.

5

Is there a workaround for CVE-2011-0538?

There are no known workarounds for CVE-2011-0538 other than upgrading to a patched version of Wireshark.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203