lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 31 Dec 2006 12:19:59 +0100
Subject: ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution

Synopsis:  ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
Product:   ATMEL WLAN drivers
Version:   <=

ATMEL linux PCI, PCMCIA, USB drivers. and configuration utilities.


A critical security vulnerability has been found in ATMEL WLAN drivers
Arbitrary code execution is possible.

Function Get_Wep obtains WEP key information. However, the "cname"
variable value (fuction's argument) is copied to ifr_name (attribute
of IWREQ object) without the proper bounds-checking. It leads to 
memory corruption conditions.

Affected Versions

ATMEL WLAN drivers

Kind regards,

Michał Bućko - sapheal

Powered by blists - more mailing lists