ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution Dec 31 2006 11:19AM
sapheal hack pl
Synopsis: ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution

Product: ATMEL WLAN drivers 3.4.1.1

Version: <=3.4.1.1

Product:

=======

ATMEL linux PCI, PCMCIA, USB drivers. and configuration utilities.

Issue:

======

A critical security vulnerability has been found in ATMEL WLAN drivers 3.4.1.1.

Arbitrary code execution is possible.

Details:

========

Function Get_Wep obtains WEP key information. However, the "cname"

variable value (fuction's argument) is copied to ifr_name (attribute

of IWREQ object) without the proper bounds-checking. It leads to

memory corruption conditions.

Affected Versions

=================

ATMEL WLAN drivers 3.4.1.1

Kind regards,

Micha³ Buæko - sapheal

HACK.PL

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus