CVE-2011-1140

Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allow remote attackers to cause a denial of service (infinite recursion) via a crafted (1) SMB or (2) Connection-less LDAP (CLDAP) packet.
Severity
UNKNOWN
AV:N/AC:M/Au:N/C:N/I:N/A:P
Atk. Vector
NETWORK
Atk. Complexity
MEDIUM
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
wiresharkwireshark
1.0
wiresharkwireshark
1.0.0
wiresharkwireshark
1.0.1
wiresharkwireshark
1.0.2
wiresharkwireshark
1.0.3
wiresharkwireshark
1.0.4
wiresharkwireshark
1.0.5
wiresharkwireshark
1.0.6
wiresharkwireshark
1.0.7
wiresharkwireshark
1.0.8
wiresharkwireshark
1.0.9
wiresharkwireshark
1.0.10
wiresharkwireshark
1.0.11
wiresharkwireshark
1.0.12
wiresharkwireshark
1.0.13
wiresharkwireshark
1.0.14
wiresharkwireshark
1.0.15
wiresharkwireshark
1.0.16
wiresharkwireshark
1.2.0
wiresharkwireshark
1.2.1
wiresharkwireshark
1.2.2
wiresharkwireshark
1.2.3
wiresharkwireshark
1.2.4
wiresharkwireshark
1.2.5
wiresharkwireshark
1.2.6
wiresharkwireshark
1.2.7
wiresharkwireshark
1.2.8
wiresharkwireshark
1.2.9
wiresharkwireshark
1.2.10
wiresharkwireshark
1.2.11
wiresharkwireshark
1.2.12
wiresharkwireshark
1.2.13
wiresharkwireshark
1.2.14
wiresharkwireshark
1.4.0
wiresharkwireshark
1.4.1
wiresharkwireshark
1.4.2
wiresharkwireshark
1.4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wireshark
bullseye
3.4.10-0+deb11u1
fixed
bullseye (security)
3.4.16-0+deb11u1
fixed
bookworm
4.0.11-1~deb12u1
fixed
bookworm (security)
4.0.11-1~deb12u1
fixed
trixie
4.4.0-1
fixed
sid
4.4.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wireshark
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
Fixed 1.2.11-6+squeeze1build0.10.10.1
released
lucid
ignored
karmic
ignored
hardy
ignored
dapper
dne
Common Weakness Enumeration
References