CVE-2011-1140

Wireshark - Resource Management Error

Title source: rule

Description

Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/wireshark/cldap.rb

References (25)

... and 5 more

Scores

EPSS 0.3077
EPSS Percentile 96.7%

Details

CWE
CWE-399
Status published
Products (37)
wireshark/wireshark 1.0
wireshark/wireshark 1.0.0
wireshark/wireshark 1.0.1
wireshark/wireshark 1.0.2
wireshark/wireshark 1.0.3
wireshark/wireshark 1.0.4
wireshark/wireshark 1.0.5
wireshark/wireshark 1.0.6
wireshark/wireshark 1.0.7
wireshark/wireshark 1.0.8
... and 27 more
Published Mar 03, 2011
Tracked Since Feb 18, 2026