Summary
This host is installed with Wireshark and is prone to code execution and denial of service vulnerabilities.
Impact
Successful exploitation will allow the attacker to execute arbitrary script in the context of the affected application and denial of service condition.
Impact Level: System/Application
Solution
Upgrade to the Wireshark version 1.4.9, 1.6.2 or later, For updates refer to http://www.wireshark.org/download
Insight
The flaws are due to
- An unspecified error related to Lua scripts, which allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.
- An error in 'IKEv1' protocol dissector and 'proto_tree_add_item()', when add more than 1000000 items to a proto_tree, that will cause a denial of service.
Affected
Wireshark versions 1.4.x before 1.4.9 and 1.6.x before 1.6.2 on Mac OS X
References
Severity
Classification
-
CVE CVE-2011-3266, CVE-2011-3360 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Air Code Execution and DoS Vulnerabilities (Windows)
- Adobe Acrobat Multiple Vulnerabilities-01 Sep14 (Mac OS X)
- Adobe Acrobat Multiple Vulnerabilities-01 Dec14 (Windows)
- Adobe AIR Multiple Vulnerabilities(APSB14-22)-(Windows)
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Linux)