CVE-2011-4100Wireshark vulnerability

CWE-3996 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.0%
top 22.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 3
Latest updateMay 17

Description

The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/wireshark< wireshark 1.6.3-1 (bookworm)
Debianwireshark/wireshark< 1.6.3-1+3
NVDwireshark/wireshark1.6.0, 1.6.1, 1.6.2+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-43qp-rp4g-mx9r: The csnStreamDissector function in epan/dissectors/packet-csn12022-05-17
OSV
CVE-2011-4100: The csnStreamDissector function in epan/dissectors/packet-csn12011-11-03

📋Vendor Advisories

2
Red Hat
wireshark: uninitialized variable in the CSN.1 dissector can cause a crash2011-09-16
Debian
CVE-2011-4100: wireshark - The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 di...2011

💬Community

1
Bugzilla
CVE-2011-4100 wireshark: uninitialized variable in the CSN.1 dissector can cause a crash2011-11-01