CVE-2011-2597

Wireshark 1.2.x < 1.2.18, 1.4.x <= 1.4.7, 1.6.0 - Denial of Service via Lucent/Ascend File Parser

Title source: llm
STIX 2.1

Description

The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.

References (15)

Core 15
Core References
Various Sources x_refsource_confirm
http://www.wireshark.org/security/wnpa-sec-2011-10.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1025738
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45574
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68335
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48947
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063586.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48506
Various Sources x_refsource_confirm
http://www.wireshark.org/security/wnpa-sec-2011-11.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063591.html
Various Sources x_refsource_confirm
http://www.wireshark.org/security/wnpa-sec-2011-09.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45086
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14794
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:118

Scores

EPSS 0.0127
EPSS Percentile 79.8%

Details

CWE
CWE-399
Status published
Products (28)
wireshark/wireshark 1.2
wireshark/wireshark 1.2.0
wireshark/wireshark 1.2.1
wireshark/wireshark 1.2.2
wireshark/wireshark 1.2.3
wireshark/wireshark 1.2.4
wireshark/wireshark 1.2.5
wireshark/wireshark 1.2.6
wireshark/wireshark 1.2.7
wireshark/wireshark 1.2.8
... and 18 more
Published Jul 07, 2011
Tracked Since Feb 18, 2026