[NEWS] Marvell Driver EAPoL-Key Length Overflow



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Marvell Driver EAPoL-Key Length Overflow
------------------------------------------------------------------------


SUMMARY

The wireless drivers in some Wi-Fi access points (such as the
MARVELL-based Netgear WN802T) do not correctly parse malformed EAPoL-Key
packets. This packet is used for unicast/multicast key derivation (which
are called 4-way handshake and group key handshake) of any secure wireless
connection (WPA-PSK, WPA2-PSK, WPA-EAP, WPA2-EAP).

DETAILS

Vulnerable Systems:
* Netgear WN802T (firmware 1.3.16) with MARVELL 88W8361P-BEM1 chipset

The bug can be triggered by a malicious EAPoL-Key packet sent to the
wireless access point (this packet has an advertised length too long
triggering the overflow). This can be achieved only after a successful
802.11 authentication (in "Open" mode according to the configuration of
the wireless access point) and a successful 802.11 association with
appropriate security parameters (e.g. WPA w/ TKIP unicast, TKIP multicast)
which depends on the configuration of the wireless access point.

Attack Impact:
Denial-of-service (reboot or hang-up) and possibly remote arbitrary code
execution

Attack Vector:
Unauthenticated wireless device for WPA/WPA2-PSK and EAP-based
authenticated wireless device for WPA/WPA2-EAP

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1144>
CVE-2008-1144


ADDITIONAL INFORMATION

The information has been provided by
<mailto:laurent.butti@xxxxxxxxxxxxxxxxxx> Laurent Butti and Julien Tinnes.



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] Microsoft Windows Wireless Zero Multiple Vulnerabilities (Information Disclosure, Authenticatio
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Windows Wireless Zero Multiple Vulnerabilities (Information ... int psk_length; ... unsigned char psk; ...
    (Securiteam)
  • [NT] WEP Open Authentication Information Disclosure
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... post-association connection with the attacker in the clear. ... Certain well-known wireless chipsets, ... WEP-client-communication-dumbdown or WCCD vulnerability. ...
    (Securiteam)
  • [NEWS] Insecure FTP Access in HP PSC 2510 Printers
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... PSC 2510 Photosmart all-in-one printer/flatbed fax/scanner/copier device ... built-in wireless and wired technology for home networks, ... Insecure FTP server in the HP PSC 2510 printer allows unauthenticated ...
    (Securiteam)
  • [NT]Microsoft Windows WRITE_ANDX SMB Command Handling Kernel DoS
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Windows Vista SP1 with latest security updates ... Invalid system memory was referenced. ... Srv.sys is the driver that will process the received SMB packet, ...
    (Securiteam)
  • [NT] Timbuktu Pro Path Traversal and Log Injection
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Several fields of the packet ... The other bug is a logging file content manipulation vulnerability ... chunk should be set ...
    (Securiteam)