PT-2008-1105 · Linux+1 · Linux Kernel+1

Anders Kaseorg

+1

·

Publicado

2008-11-06

·

Atualizado

2017-08-08

·

CVE-2008-4395

CVSS v2.0

8.3

Alta

VetorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ndiswrapper versions prior to 1.53-r1
Description The issue affects the ndiswrapper package in Gentoo Linux and the Linux kernel 2.6, allowing remote attackers to execute arbitrary code by sending packets over a local wireless network with long ESSIDs, potentially compromising confidentiality, integrity, and availability of protected information.
Recommendations For ndiswrapper versions prior to 1.53-r1, update to version 1.53-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to wireless networks to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09361
CVE-2008-4395
DSA-1731-1

Produtos afetados

Linux Kernel
Ndiswrapper