lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [month] [year] [list]
Date: Sun, 31 Dec 2006 12:19:59 +0100
From: sapheal@...k.pl
To: bugtraq@...urityfocus.com
Subject: ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution

Synopsis:  ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
Product:   ATMEL WLAN drivers 3.4.1.1
Version:   <=3.4.1.1


Product:
=======
ATMEL linux PCI, PCMCIA, USB drivers. and configuration utilities.


Issue:
======

A critical security vulnerability has been found in ATMEL WLAN drivers 3.4.1.1.
Arbitrary code execution is possible.

Details:
========
Function Get_Wep obtains WEP key information. However, the "cname"
variable value (fuction's argument) is copied to ifr_name (attribute
of IWREQ object) without the proper bounds-checking. It leads to 
memory corruption conditions.

Affected Versions
=================

ATMEL WLAN drivers 3.4.1.1



Kind regards,

Micha³ Buæko - sapheal
HACK.PL

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux