Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
From: sapheal () hack pl
Date: Sun, 31 Dec 2006 12:19:59 +0100

Synopsis:  ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
Product:   ATMEL WLAN drivers 3.4.1.1
Version:   <=3.4.1.1


Product:
=======
ATMEL linux PCI, PCMCIA, USB drivers. and configuration utilities.


Issue:
======

A critical security vulnerability has been found in ATMEL WLAN drivers 3.4.1.1.
Arbitrary code execution is possible.

Details:
========
Function Get_Wep obtains WEP key information. However, the "cname"
variable value (fuction's argument) is copied to ifr_name (attribute
of IWREQ object) without the proper bounds-checking. It leads to 
memory corruption conditions.

Affected Versions
=================

ATMEL WLAN drivers 3.4.1.1



Kind regards,

Michał Bućko - sapheal
HACK.PL

  By Date           By Thread  

Current thread:
  • ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution sapheal (Jan 01)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]