Summary
The host is installed with Wireshark and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow remote attackers to cause a denial of service.
Impact Level: Application
Solution
Upgrade to the Wireshark version 1.4.4 or 1.2.15
For updates refer to http://www.wireshark.org/download.html
Insight
The flaws are due to
- Multiple stack consumption vulnerabilities in the 'dissect_ms_compressed_string' and 'dissect_mscldap_string functions' - Error in 'epan/dissectors/packet-ldap.c' which allows attackers to cause a denial of service via a long LDAP filter string or an LDAP filter string containing many elements.
Affected
Wireshark 1.0.x
Wireshark version 1.2.0 through 1.2.14
Wireshark version 1.4.0 through 1.4.3
References
Severity
Classification
-
CVE CVE-2011-1140, CVE-2011-1141 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities