CVE-2011-0024
published 2011-03-28CVE-2011-0024: Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.96%
91.3th percentile
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.2-0-1 (bookworm) | wireshark 1.2-0-1 (bookworm) |
| wireshark | wireshark | <= 1.0.16 | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v7qp-r7xw-hqm2: Heap-based buffer overflow in wiretap/pcapng
ghsa_unreviewed·2022-05-03
CVE-2011-0024 [HIGH] CWE-119 GHSA-v7qp-r7xw-hqm2: Heap-based buffer overflow in wiretap/pcapng
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
OSV
CVE-2011-0024: Heap-based buffer overflow in wiretap/pcapng
osv·2011-03-28·CVSS 9.3
CVE-2011-0024 [CRITICAL] CVE-2011-0024: Heap-based buffer overflow in wiretap/pcapng
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
Red Hat
wireshark: heap-based buffer overflow in wireshark < 1.2 when reading malformed capture files
vendor_redhat·2011-03-21·CVSS 9.3
CVE-2011-0024 [CRITICAL] CWE-122 wireshark: heap-based buffer overflow in wireshark < 1.2 when reading malformed capture files
wireshark: heap-based buffer overflow in wireshark < 1.2 when reading malformed capture files
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-0024: wireshark - Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows re...
vendor_debian·2011·CVSS 9.3
CVE-2011-0024 [CRITICAL] CVE-2011-0024: wireshark - Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows re...
Heap-based buffer overflow in wiretap/pcapng.c in Wireshark before 1.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted capture file.
Scope: local
bookworm: resolved (fixed in 1.2-0-1)
bullseye: resolved (fixed in 1.2-0-1)
forky: resolved (fixed in 1.2-0-1)
sid: resolved (fixed in 1.2-0-1)
trixie: resolved (fixed in 1.2-0-1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/43821http://www.redhat.com/support/errata/RHSA-2011-0370.htmlhttp://www.vupen.com/english/advisories/2011/0719https://bugzilla.redhat.com/show_bug.cgi?id=671331http://secunia.com/advisories/43821http://www.redhat.com/support/errata/RHSA-2011-0370.htmlhttp://www.vupen.com/english/advisories/2011/0719https://bugzilla.redhat.com/show_bug.cgi?id=671331
2011-03-28
Published