CVE-2011-1958: Null Pointer Dereference
A NULL pointer dereference flaw was found in the way Wireshark processed certain Diameter dictionary files. A remote attacker could create a specially-crafted dictionary file, which once used, by a local, unsuspecting user when loading a Diameter capture file could lead to wireshark application crash.
References: [1] http://www.openwall.com/lists/oss-security/2011/05/31/20 (CVE request) [2] http://www.wireshark.org/security/wnpa-sec-2011-07.html (upstream advisory)
Other sources
Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Diameter dictionary file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1958?
CVE-2011-1958 is classified as a medium severity vulnerability due to its potential to cause application crashes.
How do I fix CVE-2011-1958?
To fix CVE-2011-1958, you should upgrade Wireshark to version 1.4.0 or later.
Which versions of Wireshark are affected by CVE-2011-1958?
CVE-2011-1958 affects Wireshark versions 1.2.0 through 1.2.16 and some 1.4.x versions.
Can CVE-2011-1958 be exploited remotely?
Yes, CVE-2011-1958 can be exploited remotely through a specially crafted Diameter dictionary file.
What happens if I open a malicious Diameter dictionary file with Wireshark due to CVE-2011-1958?
Opening a malicious Diameter dictionary file could lead to a null pointer dereference and cause Wireshark to crash.