Back

MEDIUM

Wireshark: Use-after-free causes heap-based buffer overflow in X.509if dissector

Published Apr 29, 2011

Description

The X.509if dissector in Wireshark 1.2.x before 1.2.16 and 1.4.x before 1.4.5 does not properly initialize certain global variables, which allows remote attackers to cause a denial of service (application crash) via a crafted .pcap file.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of wireshark package as shipped with Red Hat Enterprise Linux 4 and 5. This issue was fixed in Red Hat Enterprise Linux 6 via RHSA-2012:0509.

Metrics

Weaknesses (2)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 29, 2011
Updated Aug 6, 2024
Reserved Apr 5, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Apr 15, 2011