Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
200

Scientific Linux: 2007-12-03 Moderate: madwifi DoS Threat

Moderate: madwifi security update. Date: Mon, 3 Dec 2007 12:05:03 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for madwifi on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: madwifi security update Issue date: 2007-12-03 CVE Names: CVE-2007-5448 Madwifi 0.9.3.2 and earlier allows remote attackers to cause a denial of service (panic) via a beacon frame with a large length value in the extended supported rates (xrates) element, which triggers an assertion error, related to net80211/ieee80211_scan_ap.c and net80211/ieee80211_scan_sta.c. (CVE-2007-5448, Moderate). SL 5.x SRPMS: madwifi-0.9.3.3-12.sl5.src.rpm i386: madwifi-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.1.4.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.1.4.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.1.4.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-53.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.10.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.10.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.10.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.14.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.14.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.14.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.15.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.15.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.15.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.6.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.6.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.6.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.8.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.8.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.8.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.1.4.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.1.4.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.1.4.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-53.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.10.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.10.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.10.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.14.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.14.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.14.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.15.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.15.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.15.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.6.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.6.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.6.el5xen-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.8.el5-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.8.el5PAE-0.9.3.3-12.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.8.el5xen-0.9.3.3-12.sl5.i686.rpm x86_64: madwifi-0.9.3.3-12.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-53.1.4.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-53.1.4.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-53.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-53.el5-0.9.3.3-12.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-53.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-53.el5xen-0.9.3.3-12.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.10.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.10.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.14.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.14.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.15.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.15.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.3.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.3.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.4.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.4.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.6.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.6.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.8.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.8.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.1.4.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.1.4.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.el5-0.9.3.3-12.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-53.el5xen-0.9.3.3-12.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.10.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.10.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.14.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.14.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.15.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.15.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.6.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.6.el5xen-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.8.el5-0.9.3.3-12.el5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.8.el5xen-0.9.3.3-12.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Updated moderate madwifi security patch for Scientific Linux mitigating denial of service vulnerability through manipulated beacon packets.. madwifi security, Scientific Linux update, network security advisory, denial of service, system updates. . LinuxSecurity.com Team

Calendar 2 Dec 03, 2007 Scientific Linux
91

Gentoo: GLSA 200711-09 Normal: MadWifi Denial of Service Risk

MadWifi does not correctly process beacon frames which can lead to a remotely triggered Denial of Service.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200711-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: MadWifi: Denial of Service Date: November 07, 2007 Bugs: #195705 ID: 200711-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= MadWifi does not correctly process beacon frames which can lead to a remotely triggered Denial of Service. Background ========= The MadWifi driver provides support for Atheros based IEEE 802.11 Wireless Lan cards. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.3.3 > = 0.9.3.3 Description ========== Clemens Kolbitsch and Sylvester Keil reported an error when processing beacon frames with an overly large "length" value in the "xrates" element. Impact ===== A remote attacker could act as an access point and send a specially crafted packet to an Atheros based wireless client, possibly resulting in a Denial of Service (kernel panic). Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.3.3" References ========= [ 1 ] CVE-2007-5448 https://www.cve.org/CVERecord?id=CVE-2007-5448 Availability =========== This GLSA and any updates to itare available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200711-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFHMiNtuhJ+ozIKI5gRAoxqAKCEmLB5pbn+EQSnNvbJAcoMe3XbGwCgoeyZ 9aD3ruieUHJOEeCYrR/ihTs=7I0H -----END PGP SIGNATURE----- . Unauthorized users may leverage vulnerabilities in MadWifi to trigger service disruptions. Ensure you update to the most current release to protect your network.. MadWifi Denial of Service,Gentoo Advisory,Linux Security Update,Network Vulnerability. . LinuxSecurity.com Team

Calendar 2 Nov 07, 2007 Gentoo
200

SciLinux: Security Fixes in Madwifi 0.9.3.1 for SL5.x and SL4.x

Madwifi 0.9.3.1 fixes three security vulnerabilitie.. Date: Fri, 8 Jun 2007 16:28:18 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for madwifi on SL5.x, SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Madwifi 0.9.3.1 fixes three security vulnerabilitie. Issue date: 2007-05-23 CVE Names: Madwifi 0.9.3.1 Release note: Security fixes in 0.9.3.1: - In the madwifi/ath component if_ath.c handles the beacon configuration related initialization task both for clients and aps in the function ath_beacon_config(). The function uses macro "howmany" which performs divide operation. The macro is used without ensuring that the argument(denominator 'intval') could be zero. The divide by zero condition can be triggered externally using a malformed packet. - There is a vulnerability in packet parsing code whereby a remote attacker can craft a malicious packet that will DoS the system. Due to improper sanitization of nested 802.3 Ethernet frame length fields in Fast Frame packets, the MadWifi driver is vulnerable to a remote kernel denial of service. The problem is that the frame length is read directly from the attackers packet without validation. The attacker can specify a length so that after the skb_pull operation skb1 is less than sizeof(ethernet_header). When skb_pull is called again on skb1 in athff_decap it will return NULL. This results in a NULL dereference later on in the function. - A restricted local user can make an unprivileged I/O control call to the driver's ieee80211_ioctl_getwmmparams. This function accepts an array index from the user, which is validated incorrectly. The function checks that the index supplied by the user is less than a maximum value, but does not check if the index is less than 0. A local attacker can specify a large negative number which will pass the check, and cause an error in the array dereference. NOTE: The version number 0.9.3.1 is actually lower than the versionnumber shipped in Scientific Linux 4.x. This is correct. This really is the latest version of madwifi. We have adjusted the rpm's so that they can handle this. SL 4.x SRPMS: madwifi-0.9.3.1-10.sl4.src.rpm i386: madwifi-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.10.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.10.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.10.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.3.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.3.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.3.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.8.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.8.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-42.0.8.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.ELsmp-0.9.3.1-10.sl4.i686.rpm x86_64: madwifi-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.10.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.10.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.10.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.3.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.3.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.3.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.8.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.8.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-42.0.8.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.10.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.3.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-42.0.8.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.ELsmp-0.9.3.1-10.sl4.x86_64.rpm SL 5.x SRPMS: madwifi-0.9.3.1-11.sl5.src.rpm i386: madwifi-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5PAE-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.3.el5xen-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5PAE-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-2.6.18-8.1.4.el5xen-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5PAE-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5xen-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5PAE-0.9.3.1-11.sl5.i686.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5xen-0.9.3.1-11.sl5.i686.rpm x86_64: madwifi-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.3.el5-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.3.el5xen-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.4.el5-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-2.6.18-8.1.4.el5xen-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.3.el5xen-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5-0.9.3.1-11.sl5.x86_64.rpm kernel-module-madwifi-hal-2.6.18-8.1.4.el5xen-0.9.3.1-11.sl5.x86_64.rpm -Connie Sieh -Troy Dawson . Madwifi 0.9.3.1 addresses several vulnerabilities that could lead to service interruptions and potential security threats on Scientific Linux.. madwifi security, linux errata, denial of service fix, scientific linux updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 08, 2007 Important Scientific Linux
91

Gentoo: 200704-15 Normal: MadWifi Driver DoS Threats Identified

Multiple vulnerabilities have been discovered in the MadWifi driver, possibly leading to a Denial of Service and information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200704-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: MadWifi: Multiple vulnerabilities Date: April 17, 2007 Bugs: #173434 ID: 200704-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in the MadWifi driver, possibly leading to a Denial of Service and information disclosure. Background ========= The MadWifi driver provides support for Atheros based IEEE 802.11 Wireless Lan cards. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.3 > = 0.9.3 Description ========== The driver does not properly process Channel Switch Announcement Information Elements, allowing for an abnormal channel change. The ieee80211_input() function does not properly handle AUTH frames and the driver sends unencrypted packets before WPA authentication succeeds. Impact ===== A remote attacker could send specially crafted AUTH frames to the vulnerable host, resulting in a Denial of Service by crashing the kernel. A remote attacker could gain access to sensitive information about network architecture by sniffing unencrypted packets. A remote attacker could also send a Channel Switch Count less than or equal to one to trigger a channel change, resulting in a communication loss and a Denial ofService. Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.3" References ========= [ 1 ] CVE-2007-7178 https://www.cve.org/CVERecord?id=CVE-2006-7178 [ 2 ] CVE-2007-7179 https://www.cve.org/CVERecord?id=CVE-2006-7179 [ 3 ] CVE-2007-7180 https://www.cve.org/CVERecord?id=CVE-2006-7180 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200704-15 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Investigate weaknesses in the MadWifi driver responsible for potential Denial of Service (DoS) attacks and data leaks. For comprehensive advisory information, review the complete report.. MadWifi Security, Gentoo Advisory, Driver Issues, Linux Networking. . LinuxSecurity.com Team

Calendar 2 Apr 18, 2007 Gentoo
100

SUSE: 2006-074 Critical: Madwifi Remote Code Execution Threat

The madwifi-ng Atheros Wireless LAN card driver is subject to The madwifi-ng Atheros Wireless LAN card driver is subject to a remotely exploitable stack buffer overflow, which either code a remotely exploitable stack buffer overflow, which either code execution possibility or at least a denial of service (kernel crash). A physical local attacker (within WLAN range) has to provide an malicious acc [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Announcement Package: madwifi Announcement ID: SUSE-SA:2006:074 Date: Mon, 11 Dec 2006 18:00:00 +0000 Affected Products: SUSE SLED 10 SUSE Linux 9.3 SUSE Linux 10.0 Vulnerability Type: remote code execution Severity (1-10): 10 SUSE Default Package: yes Cross-References: CVE-2006-6332 Content of This Advisory: 1) Security Vulnerability Resolved: Atheros WLAN driver remote root exploit Problem Description 2) Solution or Work-Around 3) Special Instructions and Notes 4) Package Location and Checksums 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. 6) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Problem Description and Brief Discussion The madwifi-ng Atheros Wireless LAN card driver is subject to a remotely exploitable stack buffer overflow, which either code execution possibility or at least a denial of service (kernel crash). A physical local attacker (within WLAN range) has to provide an malicious access point which the card tries to associate with to be able to effect this attack. This issue is tracked by theMitre CVE ID CVE-2006-6332. This update also brings the madwifi driver to version 0.9.2.1. Affected SUSE Linux products: SUSE Linux Desktop 10 - Code execution is possible when this problem is exploited. Fixed madwifi-kmp-* packages are available and linked from this advisory. SUSE Linux 9.3 and 10.0 - These distributions use an older madwifi driver version, where an attacker can only overflow the buffer with hex characters, making code execution nearly impossible but a denial of service (crash) still likely. Updates for 9.3 and 10.0 are in preparation and will be in the next kernel security update. Other SUSE Linux versions do not ship the madwifi driver or are not vulnerable to this problem. For SUSE Linux 10.1 and openSUSE 10.2 the Madwifi community provides fixed driver modules and a new driver module layout on 2) Solution or Work-Around There is no known workaround, please install the update packages. 3) Special Instructions and Notes It is sufficient to rmmod and then modprobe the "ath_pci" kernel module after installing the update. The recommended way to get a known good state is to reboot the machine. 4) Package Location and Checksums The preferred method for installing security updates is to use the YaST Online Update (YOU) tool. YOU detects which updates are required and automatically performs the necessary steps to verify and install them. Alternatively, download the update packages for your distribution manually and verify their integrity by the methods listed in Section 6 of this announcement. Then install the packages using the command rpm -Fhv to apply the update, replacing with the filename of the downloaded RPM package. Our maintenance customers are notified individually. The packages are offered for installation from the maintenance web: SUSE SLED 10 http://support.novell.com/techcenter/psdb/3416396e4a9f8f1824b11dc72bbdce3e.html ______________________________________________________________________________ 5) Pending Vulnerabilities, Solutions, and Work-Arounds: See SUSE Security Summary Report. ______________________________________________________________________________ 6) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file where you saved the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and the integrity of a package needs to be verified to ensure that it has not been tampered with. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or RPM package: 1) Using the internal gpg signatures of the rpm package 2) MD5 checksums as provided in this announcement 1) The internal rpm package signatures providean easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and at the end of this announcement. 2) If you need an alternative means of verification, use the md5sum command to verify the authenticity of the packages. Execute the command md5sum after you downloaded the file from a SUSE FTP server or its mirrors. Then compare the resulting md5sum with the one that is listed in the SUSE security announcement. Because the announcement containing the checksums is cryptographically signed (by This email address is being protected from spambots. You need JavaScript enabled to view it.), the checksums show proof of the authenticity of the package if the signature of the announcement is valid. Note that the md5 sums published in the SUSE Security Announcements are valid for the respective packages only. Newer versions of these packages cannot be verified. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . For general information or the frequently asked questions (FAQ), send mail to or . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . Urgent security patch released for madwifi Atheros driver on SUSE products to mitigate severe remote code execution vulnerabilities.. madwifi-ng, Atheros, WLAN driver, remote exploit, security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 11, 2006 Critical SuSE
91

Gentoo GLSA-202312-05: Critical Audacious Remote Code Execution Issue

MadWifi is vulnerable to a buffer overflow that could potentially lead to the remote execution of arbitrary code with root privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: MadWifi: Kernel driver buffer overflow Date: December 10, 2006 Bugs: #157449 ID: 200612-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= MadWifi is vulnerable to a buffer overflow that could potentially lead to the remote execution of arbitrary code with root privileges. Background ========= MadWifi (Multiband Atheros Driver for Wireless Fidelity) provides a Linux kernel device driver for Atheros-based Wireless LAN devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.2.1 > = 0.9.2.1 Description ========== Laurent Butti, Jerome Raznieski and Julien Tinnes reported a buffer overflow in the encode_ie() and the giwscan_cb() functions from ieee80211_wireless.c. Impact ===== A remote attacker could send specially crafted wireless WPA packets containing malicious RSN Information Headers (IE) that could potentially lead to the remote execution of arbitrary code as the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.2.1" References ========= [ 1 ] CVE-2006-6332 https://www.cve.org/CVERecord?id=CVE-2006-6332 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200612-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The MadWifi driver on Gentoo contains a vulnerability that could enable unauthorized remote code execution via a buffer overflow. Upgrading is recommended to enhance security. MadWifi, Kernel Driver, Remote Code Execution, Gentoo, Buffer Overflow. . LinuxSecurity.com Team

Calendar 2 Dec 10, 2006 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here