CVE-2011-1138Off-by-one Error in Wireshark

Severity
4.3MEDIUMNVD
EPSS
3.8%
top 11.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateMay 17

Description

Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wireshark 1.4.0 through 1.4.3 on 32-bit platforms allows remote attackers to cause a denial of service (application crash) via a malformed 6LoWPAN IPv6 packet.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.4.4-1 (bookworm)
Debianwireshark/wireshark< 1.4.4-1+3
NVDwireshark/wireshark4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4fvr-jf76-h7qr: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan2022-05-17
OSV
CVE-2011-1138: Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan2011-03-03

📋Vendor Advisories

2
Red Hat
Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)2011-03-01
Debian
CVE-2011-1138: wireshark - Off-by-one error in the dissect_6lowpan_iphc function in packet-6lowpan.c in Wir...2011

💬Community

2
Bugzilla
CVE-2011-1138 Wireshark: Off-by-one error in the dissect_6lowpan_iphc function causes application crash (Denial Of Service)2011-03-03
Bugzilla
CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]2011-02-11