RULE(RULE ID:1905821)

Rule General Information
Release Date: 2019-08-20
Rule Name: Wireshark Insecure Search Path Script Execution Vulnerability -2 (CVE-2011-3360)
Severity:
CVE ID:
Rule Protection Details
Description: Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: http://www.debian.org/security/2011/dsa-2324
http://www.mandriva.com/security/advisories?name=MDVSA-2011:138
http://www.openwall.com/lists/oss-security/2011/09/13/1
http://www.openwall.com/lists/oss-security/2011/09/14/5
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.wireshark.org/download.html