The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE packet and many items in a tree.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade wireshark | Jul 30, 2024 | Aug 24, 2011 |
| Gentoo Linux | — | Upgrade net-analyzer/wireshark. | Oct 30, 2017 | Aug 23, 2011 |
| Oracle Solaris | — | Upgrade diagnostic/wireshark/tshark to version 1.4.10-0.175.0.2.0.2.0 on Solaris 11.0Upgrade diagnostic/wireshark to version 1.4.10-0.175.0.2.0.2.0 on Solaris 11.0Upgrade diagnostic/wireshark/wireshark-common to version 1.4.10-0.175.0.2.0.2.0 on Solaris 11.0 | May 29, 2017 | Aug 23, 2011 |
| Suse | — | Upgrade wiresharkUpgrade wireshark-develUpgrade libwiretap15Upgrade libwscodecs1Upgrade libwiretap16Upgrade libwsutil17Upgrade wireshark-ui-qtUpgrade libwsutil7Upgrade libwiretap6Upgrade wireshark-gtkUpgrade libwiretap7Upgrade libwireshark18Upgrade libwireshark8Upgrade libwsutil16Upgrade libwireshark9Upgrade libwsutil8Upgrade libwireshark19 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade wireshark | Nov 19, 2024 | Aug 24, 2011 |
| Wireshark | — | Upgrade to Wireshark version 1.4.9Upgrade to Wireshark version 1.6.2 | Oct 4, 2017 | Aug 23, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub