Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200711-09 ] MadWifi: Denial of Service
Date: Wed, 07 Nov 2007 20:57:34
Message-Id: 4732236E.3090306@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200711-09
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: MadWifi: Denial of Service
12 Date: November 07, 2007
13 Bugs: #195705
14 ID: 200711-09
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 MadWifi does not correctly process beacon frames which can lead to a
22 remotely triggered Denial of Service.
23
24 Background
25 ==========
26
27 The MadWifi driver provides support for Atheros based IEEE 802.11
28 Wireless Lan cards.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 net-wireless/madwifi-ng < 0.9.3.3 >= 0.9.3.3
37
38 Description
39 ===========
40
41 Clemens Kolbitsch and Sylvester Keil reported an error when processing
42 beacon frames with an overly large "length" value in the "xrates"
43 element.
44
45 Impact
46 ======
47
48 A remote attacker could act as an access point and send a specially
49 crafted packet to an Atheros based wireless client, possibly resulting
50 in a Denial of Service (kernel panic).
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All MadWifi users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose ">=net-wireless/madwifi-ng-0.9.3.3"
64
65 References
66 ==========
67
68 [ 1 ] CVE-2007-5448
69 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5448
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200711-09.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 http://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2007 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5
98 -----BEGIN PGP SIGNATURE-----
99 Version: GnuPG v1.4.7 (GNU/Linux)
100 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
101
102 iD8DBQFHMiNtuhJ+ozIKI5gRAoxqAKCEmLB5pbn+EQSnNvbJAcoMe3XbGwCgoeyZ
103 9aD3ruieUHJOEeCYrR/ihTs=
104 =7I0H
105 -----END PGP SIGNATURE-----
106 --
107 gentoo-announce@g.o mailing list