CVE-2011-1140: Medium severity wireshark vulnerability
Multiple stack consumption vulnerabilities in the dissectmscompressedstring and dissectmscldapstring functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1140?
CVE-2011-1140 is classified as a high-severity vulnerability due to its potential to cause denial of service through infinite recursion.
How do I fix CVE-2011-1140?
To mitigate CVE-2011-1140, upgrade Wireshark to the latest version that is not affected by this vulnerability, specifically versions 1.4.4 and above.
What versions of Wireshark are affected by CVE-2011-1140?
CVE-2011-1140 affects Wireshark versions 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3.
What are the potential impacts of CVE-2011-1140?
The potential impact of CVE-2011-1140 includes a denial of service attack resulting in application crashes due to stack consumption.
Is there a workaround for CVE-2011-1140?
There is no defined workaround for CVE-2011-1140; upgrading to a fixed version is the recommended approach.