Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-1140Wireshark vulnerability

CWE-3998 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
30.8%
top 3.26%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 3
Latest updateMay 17

Description

Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.4.4-1 (bookworm)
Debianwireshark/wireshark< 1.4.4-1+3
NVDwireshark/wireshark37 versions+36

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rjw2-p6xh-g64w: Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 12022-05-17
OSV
CVE-2011-1140: Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 12011-03-03

💥Exploits & PoCs

1
Metasploit
Wireshark CLDAP Dissector DOS

📋Vendor Advisories

2
Red Hat
Wireshark: Multiple stack consumption vulnerabilities caused DoS via crafted SMB or CLDAP packet2011-03-01
Debian
CVE-2011-1140: wireshark - Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string a...2011

💬Community

2
Bugzilla
CVE-2011-1140 Wireshark: Multiple stack consumption vulnerabilities caused DoS via crafted SMB or CLDAP packet2011-03-03
Bugzilla
CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]2011-02-11