CVE-2011-1141Wireshark vulnerability

CWE-3997 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.9%
top 16.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 3
Latest updateMay 17

Description

epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.4.4-1 (bookworm)
Debianwireshark/wireshark< 1.4.4-1+3
NVDwireshark/wireshark37 versions+36

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m4vw-5hvc-7fj2: epan/dissectors/packet-ldap2022-05-17
OSV
CVE-2011-1141: epan/dissectors/packet-ldap2011-03-03

📋Vendor Advisories

2
Red Hat
Wireshark: Malformed LDAP filter string causes Denial of Service via excessive memory consumption2011-03-01
Debian
CVE-2011-1141: wireshark - epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4....2011

💬Community

2
Bugzilla
CVE-2011-1141 Wireshark: Malformed LDAP filter string causes Denial of Service via excessive memory consumption2011-03-03
Bugzilla
CVE-2011-0538 CVE-2010-3445 CVE-2011-1143 CVE-2011-1140 CVE-2011-1138 CVE-2011-1139 wireshark various flaws [fedora-all]2011-02-11