First published: Thu Jul 28 2011(Updated: )
It was found that wireshark could run arbitrary Lua scripts. Reference: <a href="http://www.wireshark.org/security/wnpa-sec-2011-15.html">http://www.wireshark.org/security/wnpa-sec-2011-15.html</a> This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories: <a href="https://admin.fedoraproject.org/updates/FEDORA-2011-12423">https://admin.fedoraproject.org/updates/FEDORA-2011-12423</a> <a href="https://admin.fedoraproject.org/updates/FEDORA-2011-12403">https://admin.fedoraproject.org/updates/FEDORA-2011-12403</a> <a href="https://admin.fedoraproject.org/updates/FEDORA-2011-12399">https://admin.fedoraproject.org/updates/FEDORA-2011-12399</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wireshark Wireshark | =1.4.7 | |
Wireshark Wireshark | =1.4.2 | |
Wireshark Wireshark | =1.4.0 | |
Wireshark Wireshark | =1.4.5 | |
Wireshark Wireshark | =1.4.4 | |
Wireshark Wireshark | =1.4.6 | |
Wireshark Wireshark | =1.4.3 | |
Wireshark Wireshark | =1.4.1 | |
Wireshark Wireshark | =1.4.8 | |
Wireshark Wireshark | =1.6.0 | |
Wireshark Wireshark | =1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3360 has a medium severity level due to the potential execution of arbitrary Lua scripts.
To fix CVE-2011-3360, upgrade Wireshark to version 1.4.9 or later.
CVE-2011-3360 affects Wireshark versions 1.4.0 to 1.4.8, including 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, and 1.4.8.
The potential risks of CVE-2011-3360 include running malicious Lua scripts, which may compromise user data or system integrity.
CVE-2011-3360 was discovered through security analysis that found Wireshark's Lua scripting capabilities could be exploited to execute arbitrary scripts.