[NEWS] Atheros Vendor Specific Information Element Overflow
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 7 Sep 2008 17:06:15 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Atheros Vendor Specific Information Element Overflow
------------------------------------------------------------------------
SUMMARY
The wireless drivers in some Wi-Fi access points (such as the
ATHEROS-based Linksys WRT350N) do not correctly parse the Atheros vendor
specific information element included in association requests. This
information element is used by wireless devices to advertise Atheros
specific capabilities.
DETAILS
Vulnerable Systems:
* Linksys WRT350N (firmware v2.00.17) with Atheros AR5416-AC1E chipset
The bug can be triggered by a malicious association request sent to the
wireless access point where one of the information elements must be an
Atheros information element with an inappropriate length (typically too
long). This can be achieved only after a successful 802.11 authentication
(in "Open" or "Shared" mode according to the configuration of the wireless
access point).
Attack Impact:
Denial-of-service (reboot or hang-up) and possibly remote arbitrary code
execution
Timeline:
2007-10-22 - Vulnerability reported to Linksys
2007-10-23 - Full details sent to Linksys
2008-09-04 - Public disclosure
CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5474>
CVE-2007-5474
ADDITIONAL INFORMATION
The information has been provided by
<mailto:laurent.butti@xxxxxxxxxxxxxxxxxx> Laurent Butti and Julien Tinnes.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NT] Google Chrome 'SaveAs' Function Buffer Overflow Vulnerability
- Next by Date: [EXPL] Samsung DVR SHR2040 HTTPD Denial of Service DoS (PoC)
- Previous by thread: [NT] Google Chrome 'SaveAs' Function Buffer Overflow Vulnerability
- Next by thread: [EXPL] Samsung DVR SHR2040 HTTPD Denial of Service DoS (PoC)
- Index(es):
Relevant Pages
|