PT-2007-6871 · Intel+1 · Iwlwifi+1

Airsupply

·

Published

2007-12-06

·

Updated

2017-09-29

·

CVE-2007-5938

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions iwlwifi versions 1.1.21 and earlier
Description The issue is related to the iwl set rate function in compatible/iwl3945-base.c, which dereferences an iwl get hw mode return value without checking for NULL. This could allow remote attackers to cause a denial of service, specifically a kernel panic, via unspecified vectors during module initialization.
Recommendations For iwlwifi versions 1.1.21 and earlier, as a temporary workaround, consider disabling the iwl set rate function until a patch is available. However, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5938
RHSA-2008:0154
RHSA-2008_0154

Affected Products

Red Hat
Iwlwifi