PT-2008-1105 · Linux+1 · Linux Kernel+1
Anders Kaseorg
+1
·
Publicado
2008-11-06
·
Atualizado
2017-08-08
·
CVE-2008-4395
CVSS v2.0
8.3
Alta
| Vetor | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ndiswrapper versions prior to 1.53-r1
Description
The issue affects the ndiswrapper package in Gentoo Linux and the Linux kernel 2.6, allowing remote attackers to execute arbitrary code by sending packets over a local wireless network with long ESSIDs, potentially compromising confidentiality, integrity, and availability of protected information.
Recommendations
For ndiswrapper versions prior to 1.53-r1, update to version 1.53-r1 or later to resolve the issue. As a temporary workaround, consider restricting access to wireless networks to minimize the risk of exploitation.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel
Ndiswrapper