CVE-2011-1591
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 42%
from disclosure to weapon0 days
Published on NVDApr 29
1st PoCApr 18
metasploitApr 18
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file.
Affected products
n/a · n/apublic PoCs found — 6
cve_referencewww.exploit-db.com/exploits/17185unverifiedcve_referencewww.exploit-db.com/exploits/17195unverifiedexploitdbwww.exploit-db.com/exploits/18145unverifiedexploitdbwww.exploit-db.com/exploits/17185unverifiedexploitdbwww.exploit-db.com/exploits/17186unverifiedexploitdbwww.exploit-db.com/exploits/17195unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.fedoraproject.org/pipermail/package-announce/2011-April/058900.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058983.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-April/058993.htmlhttp://openwall.com/lists/oss-security/2011/04/18/2http://openwall.com/lists/oss-security/2011/04/18/8https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5836https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5838http://secunia.com/advisories/44172http://secunia.com/advisories/44374http://securitytracker.com/id?1025389https://exchange.xforce.ibmcloud.com/vulnerabilities/66834https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15000