CVE-2011-3360: Critical severity wireshark vulnerability
It was found that wireshark could run arbitrary Lua scripts.
Reference: http://www.wireshark.org/security/wnpa-sec-2011-15.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Other sources
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3360?
CVE-2011-3360 has a medium severity level due to the potential execution of arbitrary Lua scripts.
How do I fix CVE-2011-3360?
To fix CVE-2011-3360, upgrade Wireshark to version 1.4.9 or later.
Which versions of Wireshark are affected by CVE-2011-3360?
CVE-2011-3360 affects Wireshark versions 1.4.0 to 1.4.8, including 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, and 1.4.8.
What are the potential risks of CVE-2011-3360?
The potential risks of CVE-2011-3360 include running malicious Lua scripts, which may compromise user data or system integrity.
How was CVE-2011-3360 discovered?
CVE-2011-3360 was discovered through security analysis that found Wireshark's Lua scripting capabilities could be exploited to execute arbitrary scripts.