CVE-2011-1138
published 2011-03-03CVE-2011-1138: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.29%
87.2th percentile
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.4.4-1 (bookworm) | wireshark 1.4.4-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.4.4-1 | 1.4.4-1 |
| wireshark | wireshark | >= 0 < 1.4.4-1 | 1.4.4-1 |
| wireshark | wireshark | >= 0 < 1.4.4-1 | 1.4.4-1 |
| wireshark | wireshark | >= 0 < 1.4.4-1 | 1.4.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
vendor_redhat·2011-03-01·CVSS 4.3
CVE-2011-1138 [MEDIUM] CWE-193 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
Statement: Not vulnerable. This issue did not affect the versions of wireshark as
shipped with Red Hat Enterprise Linux 4, 5, or 6.
Package: wireshark (Red Hat Enterprise Linux 4) - Not affected
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-1138: wireshark - Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wir...
vendor_debian·2011·CVSS 4.3
CVE-2011-1138 [MEDIUM] CVE-2011-1138: wireshark - Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wir...
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: resolved (fixed in 1.4.4-1)
forky: resolved (fixed in 1.4.4-1)
sid: resolved (fixed in 1.4.4-1)
trixie: resolved (fixed in 1.4.4-1)
GHSA
GHSA-4fvr-jf76-h7qr: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan
ghsa_unreviewed·2022-05-17
CVE-2011-1138 [MEDIUM] GHSA-4fvr-jf76-h7qr: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
OSV
CVE-2011-1138: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan
osv·2011-03-03·CVSS 4.3
CVE-2011-1138 [MEDIUM] CVE-2011-1138: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan
Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1138 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
bugzilla·2011-03-03·CVSS 4.3
CVE-2011-1138 [MEDIUM] CVE-2011-1138 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
CVE-2011-1138 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-1138 to
the following vulnerability:
Name: CVE-2011-1138
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1138
Assigned: 20110302
Reference: CONFIRM:http://anonsvn.wireshark.org/viewvc?view=rev&revision=36036
Reference: CONFIRM:http://www.wireshark.org/docs/relnotes/wireshark-1.4.4.html
Reference: CONFIRM:http://www.wireshark.org/security/wnpa-sec-2011-04.html
Reference: CONFIRM:https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5722
Off-by-one error in the dissect_6lowpan_iphc function in
packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms
allows remote attackers to
Bugzilla
CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]
bugzilla·2011-02-11·CVSS 5.0
CVE-2011-0538 [MEDIUM] CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]
CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=67
http://anonsvn.wireshark.org/viewvc?view=rev&revision=36036http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055364.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055650.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055664.htmlhttp://secunia.com/advisories/43759http://secunia.com/advisories/44169http://www.kb.cert.org/vuls/id/215900http://www.securityfocus.com/bid/46636http://www.securitytracker.com/id?1025148http://www.vupen.com/english/advisories/2011/0626http://www.wireshark.org/docs/relnotes/wireshark-1.4.4.htmlhttp://www.wireshark.org/security/wnpa-sec-2011-04.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5722https://exchange.xforce.ibmcloud.com/vulnerabilities/65783https://hermes.opensuse.org/messages/8086844https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16299http://anonsvn.wireshark.org/viewvc?view=rev&revision=36036http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055364.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055650.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055664.htmlhttp://secunia.com/advisories/43759http://secunia.com/advisories/44169http://www.kb.cert.org/vuls/id/215900http://www.securityfocus.com/bid/46636http://www.securitytracker.com/id?1025148http://www.vupen.com/english/advisories/2011/0626http://www.wireshark.org/docs/relnotes/wireshark-1.4.4.htmlhttp://www.wireshark.org/security/wnpa-sec-2011-04.htmlhttps://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5722https://exchange.xforce.ibmcloud.com/vulnerabilities/65783https://hermes.opensuse.org/messages/8086844https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16299
2011-03-03
Published