CVE-2011-1592: Medium severity wireshark vulnerability
Published Apr 29, 2011
·Updated
The NFS dissector in epan/dissectors/packet-nfs.c in Wireshark 1.4.x before 1.4.5 on Windows uses an incorrect integer data type during decoding of SETCLIENTID calls, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.
Affected Software
6 affected components
Wireshark Wireshark=1.4.0
Wireshark Wireshark=1.4.1
Wireshark Wireshark=1.4.2
Wireshark Wireshark=1.4.3
Wireshark Wireshark=1.4.4
Microsoft Windows
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 29, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
10:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1592?
CVE-2011-1592 has a medium severity rating due to potential denial of service caused by application crash.
2
How do I fix CVE-2011-1592?
To fix CVE-2011-1592, upgrade Wireshark to version 1.4.5 or later.
3
What causes the vulnerability in CVE-2011-1592?
The vulnerability in CVE-2011-1592 is caused by an incorrect integer data type during the decoding of SETCLIENTID calls.
4
Which versions of Wireshark are affected by CVE-2011-1592?
CVE-2011-1592 affects Wireshark versions 1.4.0 through 1.4.4.
5
Can CVE-2011-1592 be exploited remotely?
Yes, CVE-2011-1592 can be exploited remotely via a crafted .pcap file.