CVE-2011-1142: High severity wireshark vulnerability
Stack consumption vulnerability in the dissectberchoice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 might allow remote attackers to cause a denial of service (infinite loop) via vectors involving self-referential ASN.1 CHOICE values.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1142?
CVE-2011-1142 is classified as a denial of service vulnerability that can lead to application crashes due to stack consumption.
How do I fix CVE-2011-1142?
To fix CVE-2011-1142, upgrade to Wireshark version 1.2.16 or later, or 1.4.5 or later to mitigate the vulnerability.
What are the affected versions for CVE-2011-1142?
CVE-2011-1142 affects Wireshark versions 1.2.x up to 1.2.15 and 1.4.x up to 1.4.4.
What types of attacks can exploit CVE-2011-1142?
CVE-2011-1142 can be exploited by remote attackers using specially crafted ASN.1 CHOICE values to trigger an infinite loop.
Who is potentially affected by CVE-2011-1142?
Anyone using the affected versions of Wireshark is potentially vulnerable to attacks exploiting CVE-2011-1142.