Multiple Ralink wireless drivers: Execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200907-08 / rt2400 rt2500 rt2570 rt61 ralink-rt61 |
| Release Date |
July 12, 2009 |
| Latest Revision |
July 12, 2009: 01 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-wireless/rt2400 |
<=
1.2.2_beta3 |
|
All supported architectures
|
| net-wireless/rt2500 |
<=
1.1.0_pre2007071515 |
|
All supported architectures
|
| net-wireless/rt2570 |
<=
20070209 |
|
All supported architectures
|
| net-wireless/rt61 |
<=
1.1.0_beta2 |
|
All supported architectures
|
| net-wireless/ralink-rt61 |
<=
1.1.1.0 |
|
All supported architectures
|
Related bugreports:
#257023
Synopsis
An integer overflow in multiple Ralink wireless drivers might lead to the
execution of arbitrary code with elevated privileges.
2.
Impact Information
Background
All listed packages are external kernel modules that provide drivers
for multiple Ralink devices. ralink-rt61 is released by ralinktech.com,
the other packages by the rt2x00.serialmonkey.com project.
Description
Aviv reported an integer overflow in multiple Ralink wireless card
drivers when processing a probe request packet with a long SSID,
possibly related to an integer signedness error.
Impact
A physically proximate attacker could send specially crafted packets to
a user who has wireless networking enabled, possibly resulting in the
execution of arbitrary code with root privileges.
3.
Resolution Information
Workaround
Unload the kernel modules.
Resolution
All external kernel modules have been masked and we recommend that
users unmerge those drivers. The Linux mainline kernel has equivalent
support for these devices and the vulnerability has been resolved in
stable versions of sys-kernel/gentoo-sources.
Code Listing 3.1: Resolution |
# emerge --unmerge "net-wireless/rt2400"
# emerge --unmerge "net-wireless/rt2500"
# emerge --unmerge "net-wireless/rt2570"
# emerge --unmerge "net-wireless/rt61"
# emerge --unmerge "net-wireless/ralink-rt61"
|
4.
References
|