CVE-2011-3266
published 2011-08-24CVE-2011-3266: The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted…
PriorityP49low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
2.32%
81.7th percentile
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wireshark | < wireshark 1.6.2-1 (bookworm) | wireshark 1.6.2-1 (bookworm) |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | — | — |
| wireshark | wireshark | >= 0 < 1.6.2-1 | 1.6.2-1 |
| wireshark | wireshark | >= 0 < 1.6.2-1 | 1.6.2-1 |
| wireshark | wireshark | >= 0 < 1.6.2-1 | 1.6.2-1 |
| wireshark | wireshark | >= 0 < 1.6.2-1 | 1.6.2-1 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Wireshark proto_tree_add_item DoS
vendor_redhat·2011-07-28·CVSS 2.6
CVE-2011-3266 [LOW] Wireshark proto_tree_add_item DoS
Wireshark proto_tree_add_item DoS
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
Statement: This issue does not affect the version of wireshark shipped with Red Hat Enterprise Linux 4, 5 and 6.
Package: wireshark (Red Hat Enterprise Linux 4) - Not affected
Package: wireshark (Red Hat Enterprise Linux 5) - Not affected
Package: wireshark (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-3266: wireshark - The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 thro...
vendor_debian·2011·CVSS 2.6
CVE-2011-3266 [LOW] CVE-2011-3266: wireshark - The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 thro...
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
Scope: local
bookworm: resolved (fixed in 1.6.2-1)
bullseye: resolved (fixed in 1.6.2-1)
forky: resolved (fixed in 1.6.2-1)
sid: resolved (fixed in 1.6.2-1)
trixie: resolved (fixed in 1.6.2-1)
GHSA
GHSA-h4pp-978c-885j: The proto_tree_add_item function in Wireshark 1
ghsa_unreviewed·2022-05-14
CVE-2011-3266 [LOW] GHSA-h4pp-978c-885j: The proto_tree_add_item function in Wireshark 1
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
OSV
CVE-2011-3266: The proto_tree_add_item function in Wireshark 1
osv·2011-08-24·CVSS 2.6
CVE-2011-3266 [LOW] CVE-2011-3266: The proto_tree_add_item function in Wireshark 1
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00022.htmlhttp://securityreason.com/securityalert/8351http://securitytracker.com/id?1025875http://www.mandriva.com/security/advisories?name=MDVSA-2011:138http://www.securityfocus.com/archive/1/519049/100/0/threadedhttp://www.securityfocus.com/bid/49377http://www.wireshark.org/security/wnpa-sec-2011-13.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/69411https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15042http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00022.htmlhttp://securityreason.com/securityalert/8351http://securitytracker.com/id?1025875http://www.mandriva.com/security/advisories?name=MDVSA-2011:138http://www.securityfocus.com/archive/1/519049/100/0/threadedhttp://www.securityfocus.com/bid/49377http://www.wireshark.org/security/wnpa-sec-2011-13.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/69411https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15042
2011-08-24
Published