Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerability
BID:26842
Info
Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerability
| Bugtraq ID: | 26842 |
| Class: | Design Error |
| CVE: |
CVE-2007-5938 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2007 12:00AM |
| Updated: | Mar 05 2008 05:42PM |
| Credit: | Ian Schram discovered this issue. |
| Vulnerable: |
Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Intel iwlwifi 1.2.21 Intel iwlwifi 1.2.20 Gentoo net-wireless/iwlwifi 1.1.21-r1 |
| Not Vulnerable: |
Intel iwlwifi 1.2.22 |
Discussion
Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerability
The 'iwlwifi' drive is prone to a NULL-pointer dereference vulnerability because of a flaw in the 'compatible/iwl3945-base.c' file.
Attackers can exploit this issue to trigger a kernel panic and cause denial-of-service conditions.
Versions prior to iwlwifi 1.1.22 are vulnerable.
The 'iwlwifi' drive is prone to a NULL-pointer dereference vulnerability because of a flaw in the 'compatible/iwl3945-base.c' file.
Attackers can exploit this issue to trigger a kernel panic and cause denial-of-service conditions.
Versions prior to iwlwifi 1.1.22 are vulnerable.
Exploit / POC
Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
References
Intel Wireless WiFi Link iwlwifi NULL Pointer Dereference Vulnerability
References:
References:
- Intel Wireless WiFi Link drivers for Linux Homepage (Intel)
- net-wireless/iwlwifi < 1.1.21-r1 NULL dereference vulnerability (Gentoo)
- Questions raised when reading the (3945) code. (an Schram
telenet.be>) - RHSA-2008:0154-15 kernel security and bug fix update (Red Hat)