PT-2024-2303 · Unknown+1 · Inet Wireless Daemon+1
Alex Radocea
·
Published
2024-03-03
·
Updated
2025-01-08
·
CVE-2024-28084
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
iNet wireless daemon (IWD) versions 2.15 and earlier
Description
The issue is related to initialization problems in the p2putil.c component of the iNet wireless daemon (IWD), which can cause a denial of service (daemon crash) or possibly have other unspecified impacts when parsing of advertised service information fails. This can be exploited by a remote attacker. The vulnerability is particularly powerful as it can lead to information leaks, helping to bypass ASLR and other hardening measures. The problem occurs in the extract p2p advertised service info() function, where errors in processing can result in a double-free condition.
Recommendations
For iNet wireless daemon (IWD) versions 2.15 and earlier, consider disabling the
extract p2p advertised service info() function as a temporary workaround until a patch is available. Restrict access to the vulnerable p2putil.c component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Inet Wireless Daemon