CVE-2011-2597: Medium severity wireshark vulnerability
Published Jul 7, 2011
·Updated
The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.
Affected Software
28 affected components
Wireshark Wireshark=1.2
Wireshark Wireshark=1.2.0
Wireshark Wireshark=1.2.1
Wireshark Wireshark=1.2.2
Wireshark Wireshark=1.2.3
Wireshark Wireshark=1.2.4
Wireshark Wireshark=1.2.5
Wireshark Wireshark=1.2.6
Wireshark Wireshark=1.2.7
Wireshark Wireshark=1.2.8
Wireshark Wireshark=1.2.9
Wireshark Wireshark=1.2.10
Wireshark Wireshark=1.2.11
Wireshark Wireshark=1.2.12
Wireshark Wireshark=1.2.13
Wireshark Wireshark=1.2.14
Wireshark Wireshark=1.2.15
Wireshark Wireshark=1.2.16
Wireshark Wireshark=1.2.17
Wireshark Wireshark=1.4.0
Wireshark Wireshark=1.4.1
Wireshark Wireshark=1.4.2
Wireshark Wireshark=1.4.3
Wireshark Wireshark=1.4.4
Wireshark Wireshark=1.4.5
Wireshark Wireshark=1.4.6
Wireshark Wireshark=1.4.7
Wireshark Wireshark=1.6.0
Event History
Jul 7, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2597?
CVE-2011-2597 has a severity rating that indicates it allows remote attackers to cause a denial of service via malformed packets.
2
How do I fix CVE-2011-2597?
To fix CVE-2011-2597, upgrade to Wireshark versions 1.2.18, 1.4.8, or 1.6.1 and later.
3
What versions of Wireshark are affected by CVE-2011-2597?
CVE-2011-2597 affects Wireshark versions 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0.
4
Can CVE-2011-2597 be exploited by a local user?
CVE-2011-2597 can only be exploited by remote attackers, not local users.
5
What type of vulnerability is CVE-2011-2597?
CVE-2011-2597 is classified as a denial of service vulnerability.