wnpa-sec-2011-10 · Lucent/Ascend file parser and ANSI MAP vulnerabilities in Wireshark


Name: Lucent/Ascend file parser and ANSI MAP vulnerabilities in Wireshark

Docid: wnpa-sec-2011-10

Date: July 18, 2011

Affected versions: {{ start_version }} up to and including {{ end_version }}

Fixed versions: 1.4.8

Related: wnpa-sec-2011-11 (Lucent/Ascend file parser and ANSI MAP vulnerabilities in Wireshark version 1.6.0) wnpa-sec-2011-09 (Lucent/Ascend file parser vulnerability in Wireshark version 1.2.0 to 1.2.17)



Wireshark 1.4.8 fixes the following vulnerabilities:

  • The Lucent/Ascend file parser was susceptible to an infinite loop.
    Versions affected: 1.2.0 to 1.2.17, 1.4.0 to 1.4.7, and 1.6.0.
  • The ANSI MAP dissector was susceptible to an infinite loop. (Bug 6044)
    Versions affected: 1.4.0 to 1.4.7 and 1.6.0.


It may be possible to make Wireshark crash by injecting a series of malformed packets onto the wire or by convincing someone to read a malformed packet trace file.


Upgrade to Wireshark 1.4.8 or later. Although you can disable the ANSI MAP dissector it is not possible to work around the Lucent/Ascend parser bug.

Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE $29.95/yr
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
  • • Fully integrated with Wireshark and AirPcap™
Buy $29.95 Annual Subscription Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More

I need to capture wireless traffic...

ANSWER: AirPcap™ 802.11 Packet Capture
  • • WLAN packet capture and transmission
  • • Full 802.11 a/b/g/n support
  • • View management, control and data frames
  • • Multi-channel aggregation (with multiple adapters)
Learn More Buy Now