OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution

saphealhack.pl
Date: Sun Dec 31 2006 - 05:19:59 CST


Synopsis: ATMEL Linux PCI PCMCIA USB Drivers arbitrary code execution
Product: ATMEL WLAN drivers 3.4.1.1
Version: <=3.4.1.1


Product:
=======
ATMEL linux PCI, PCMCIA, USB drivers. and configuration utilities.


Issue:
======

A critical security vulnerability has been found in ATMEL WLAN drivers 3.4.1.1.
Arbitrary code execution is possible.

Details:
========
Function Get_Wep obtains WEP key information. However, the "cname"
variable value (fuction's argument) is copied to ifr_name (attribute
of IWREQ object) without the proper bounds-checking. It leads to
memory corruption conditions.

Affected Versions
=================

ATMEL WLAN drivers 3.4.1.1



Kind regards,

Micha│ BuŠko - sapheal
HACK.PL