CVE-2011-3483: Buffer Overflow
A buffer exception handling vulnerability was found in wireshark. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This affects versions 1.6.0 to 1.6.1 and has been fixed in version 1.6.2
Reference: http://www.wireshark.org/security/wnpa-sec-2011-14.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Other sources
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3483?
CVE-2011-3483 is considered a medium severity vulnerability as it can lead to a crash of the Wireshark application.
How do I fix CVE-2011-3483?
To fix CVE-2011-3483, upgrade Wireshark to version 1.6.2 or later.
Which versions of Wireshark are affected by CVE-2011-3483?
CVE-2011-3483 affects Wireshark versions 1.6.0 and 1.6.1.
What type of issue is CVE-2011-3483?
CVE-2011-3483 is a buffer exception handling vulnerability.
Can CVE-2011-3483 be exploited remotely?
Yes, CVE-2011-3483 can be exploited by injecting a malformed packet onto the network.