CVE-2011-3484: Input Validation
A large loop in the OpenSafety dissector could cause a crash. It may be possible to make Wireshark crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file. This affects versions 1.6.0 to 1.6.1 and has been fixed in version 1.6.2
Reference: http://www.wireshark.org/security/wnpa-sec-2011-12.html
This issue affects the versions of wireshark shipped with Fedora-14, Fedora-15 and the upcoming Fedora-16 and has been fixed via the following security advisories:
https://admin.fedoraproject.org/updates/FEDORA-2011-12423 https://admin.fedoraproject.org/updates/FEDORA-2011-12403 https://admin.fedoraproject.org/updates/FEDORA-2011-12399
Other sources
The unxorFrame function in epan/dissectors/packet-opensafety.c in the OpenSafety dissector in Wireshark 1.6.x before 1.6.2 does not properly validate a certain frame size, which allows remote attackers to cause a denial of service (loop and application crash) via a malformed packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3484?
CVE-2011-3484 has been classified as a moderate severity vulnerability that can cause application crashes.
How do I fix CVE-2011-3484?
To fix CVE-2011-3484, upgrade Wireshark to version 1.6.2 or later.
Which versions of Wireshark are affected by CVE-2011-3484?
CVE-2011-3484 affects Wireshark versions 1.6.0 and 1.6.1.
What type of attack is associated with CVE-2011-3484?
CVE-2011-3484 can be exploited through the injection of a malformed packet onto the network or by opening a manipulated packet trace file.
What happens if I encounter CVE-2011-3484?
Encountering CVE-2011-3484 may result in a crash of the Wireshark application.