Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-3483Improper Restriction of Operations within the Bounds of a Memory Buffer in Wireshark

Severity
4.3MEDIUMNVD
EPSS
6.8%
top 8.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 20
Latest updateMay 17

Description

Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.6.2-1 (bookworm)
Debianwireshark/wireshark< 1.6.2-1+3
NVDwireshark/wireshark1.6.0, 1.6.1+1

🔴Vulnerability Details

2
GHSA
GHSA-g6pq-9prm-67qv: Wireshark 12022-05-17
OSV
CVE-2011-3483: Wireshark 12011-09-20

💥Exploits & PoCs

1
Exploit-DB
Wireshark 1.6.1 - Malformed Packet Trace File Remote Denial of Service2011-09-08

📋Vendor Advisories

2
Red Hat
Wireshark: buffer exception handling vulnerability2011-09-07
Debian
CVE-2011-3483: wireshark - Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of servic...2011

💬Community

1
Bugzilla
CVE-2011-3483 Wireshark: buffer exception handling vulnerability2011-09-13