NDISwrapper: Arbitrary remote code execution
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200901-01 / ndiswrapper |
| Release Date |
January 11, 2009 |
| Latest Revision |
January 11, 2009: 01 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-wireless/ndiswrapper |
<
1.53-r1 |
>=
1.53-r1 |
All supported architectures
|
Related bugreports:
#239371
Synopsis
Multiple buffer overflows might lead to remote execution of arbitrary code
with root privileges.
2.
Impact Information
Background
NDISwrapper is a Linux kernel module that enables the use of Microsoft
Windows drivers for wireless network devices.
Description
Anders Kaseorg reported multiple buffer overflows related to long
ESSIDs.
Impact
A physically proximate attacker could send packets over a wireless
network that might lead to the execution of arbitrary code with root
privileges.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All NDISwrapper users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-wireless/ndiswrapper-1.53-r1"
|
4.
References
|