CVE-2011-1140
Wireshark 1.0.x 1.2.0-1.2.14 1.4.0-1.4.3 - Denial of Service via SMB or CLDAP Packet
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-1140.
Includes Metasploit module auxiliary/dos/wireshark/cldap.
AI-analyzed exploit summary This Metasploit module exploits a denial-of-service (DoS) vulnerability in Wireshark's CLDAP dissector by sending a malformed UDP packet, causing infinite recursion. The payload is a crafted CLDAP packet designed to trigger the vulnerability.
Description
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Exploits (1)
This Metasploit module exploits a denial-of-service (DoS) vulnerability in Wireshark's CLDAP dissector by sending a malformed UDP packet, causing infinite recursion. The payload is a crafted CLDAP packet designed to trigger the vulnerability.