OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[ GLSA 200706-04 ] MadWifi: Multiple vulnerabilities

From: Raphael Marichez (falcogentoo.org)
Date: Mon Jun 11 2007 - 16:31:29 CDT


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200706-04
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: MadWifi: Multiple vulnerabilities
      Date: June 11, 2007
      Bugs: #179532
        ID: 200706-04

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in MadWifi, possibly
allowing for the execution of arbitrary code or a Denial of Service.

Background
==========

The MadWifi driver provides support for Atheros based IEEE 802.11
Wireless Lan cards.

Affected packages
=================

    -------------------------------------------------------------------
     Package / Vulnerable / Unaffected
    -------------------------------------------------------------------
  1 net-wireless/madwifi-ng < 0.9.3.1 >= 0.9.3.1

Description
===========

Md Sohail Ahmad from AirTight Networks has discovered a divison by zero
in the ath_beacon_config() function (CVE-2007-2830). The vendor has
corrected an input validation error in the
ieee80211_ioctl_getwmmparams() and ieee80211_ioctl_getwmmparams()
functions(CVE-207-2831), and an input sanitization error when parsing
nested 802.3 Ethernet frame lengths (CVE-2007-2829).

Impact
======

An attacker could send specially crafted packets to a vulnerable host
to exploit one of these vulnerabilities, possibly resulting in the
execution of arbitrary code with root privileges, or a Denial of
Service.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All MadWifi users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-wireless/madwifi-ng-0.9.3.1"

References
==========

  [ 1 ] CVE-2007-2829
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2829
  [ 2 ] CVE-2007-2830
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2830
  [ 3 ] CVE-2007-2831
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2831

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200706-04.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
securitygentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iQEVAwUBRm2/MTvRww8BFPxFAQLfgAf+OID18hNCv/NtJjVBq7RMQ1ZhfoPS8rNM
nNNhOzqwhyl6Pi+l1mX9JypIqbDjLUOjnTR8Fs6WLbfeTXwkjtTclR1iaYtCDYxF
DaGFZRSli3DRe6e3DnXfPAO7tZUL9MiF3iCsVLi9k3ugdREIIByPd5czms16rOrh
7mXVvTmN09ZxACf2lMRcuJzfZuoFNVmhLM1i4btGmE8X9tlUv7IP5YLtO4PifeHr
we/DGz9qBYQtojjcuIw6Yu+afkfS585Qt8VsQhXtdmkNNf1SYYNw42zO8nloPqM2
HTgV+/1JsafxxJI1NHXi+eGucqVQenh7siU9dMda3ZqEHTuwsiOGlA==
=rNwb
-----END PGP SIGNATURE-----