GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Jul 12, 2009 9:26 pm Post subject: [ GLSA 200907-08 ] Multiple Ralink wireless drivers: Executi |
|
|
Gentoo Linux Security Advisory
Title: Multiple Ralink wireless drivers: Execution of arbitrary code (GLSA 200907-08)
Severity: high
Exploitable: remote
Date: July 12, 2009
Bug(s): #257023
ID: 200907-08
Synopsis
An integer overflow in multiple Ralink wireless drivers might lead to the
execution of arbitrary code with elevated privileges.
Background
All listed packages are external kernel modules that provide drivers
for multiple Ralink devices. ralink-rt61 is released by ralinktech.com,
the other packages by the rt2x00.serialmonkey.com project.
Affected Packages
Package: net-wireless/rt2400
Vulnerable: <= 1.2.2_beta3
Architectures: All supported architectures
Package: net-wireless/rt2500
Vulnerable: <= 1.1.0_pre2007071515
Architectures: All supported architectures
Package: net-wireless/rt2570
Vulnerable: <= 20070209
Architectures: All supported architectures
Package: net-wireless/rt61
Vulnerable: <= 1.1.0_beta2
Architectures: All supported architectures
Package: net-wireless/ralink-rt61
Vulnerable: <= 1.1.1.0
Architectures: All supported architectures
Description
Aviv reported an integer overflow in multiple Ralink wireless card
drivers when processing a probe request packet with a long SSID,
possibly related to an integer signedness error.
Impact
A physically proximate attacker could send specially crafted packets to
a user who has wireless networking enabled, possibly resulting in the
execution of arbitrary code with root privileges.
Workaround
Unload the kernel modules.
Resolution
All external kernel modules have been masked and we recommend that
users unmerge those drivers. The Linux mainline kernel has equivalent
support for these devices and the vulnerability has been resolved in
stable versions of sys-kernel/gentoo-sources.
Code: | # emerge --unmerge "net-wireless/rt2400"
# emerge --unmerge "net-wireless/rt2500"
# emerge --unmerge "net-wireless/rt2570"
# emerge --unmerge "net-wireless/rt61"
# emerge --unmerge "net-wireless/ralink-rt61" |
References
CVE-2009-0282
Last edited by GLSA on Fri Feb 28, 2014 4:30 am; edited 2 times in total |
|