Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
BID:31742
Info
Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
| Bugtraq ID: | 31742 |
| Class: | Design Error |
| CVE: |
CVE-2008-4441 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2008 12:00AM |
| Updated: | Oct 16 2008 05:27PM |
| Credit: | Laurent Butti and Julien Tinnes from France Telecom / Orange |
| Vulnerable: |
Marvell Semiconductor 88W8361P-BEM1 chipset 0 Linksys WAP4400N 1.2.14 |
| Not Vulnerable: | |
Discussion
Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
Linksys WAP4400N wireless access point devices are prone to a denial-of-service vulnerability because they fail to adequately verify user-supplied input.
Remote attackers can exploit this issue to hang or reboot a vulnerable device, denying service to legitimate users. Attackers may also be able to run arbitrary code, but this has not been confirmed.
Linksys WAP4400N devices running firmware 1.2.14 are vulnerable.
NOTE: Since the flaw is in the Marvell 88W8361P-BEM1 chipset driver, other devices and firmware versions using the same code may also be affected.
Linksys WAP4400N wireless access point devices are prone to a denial-of-service vulnerability because they fail to adequately verify user-supplied input.
Remote attackers can exploit this issue to hang or reboot a vulnerable device, denying service to legitimate users. Attackers may also be able to run arbitrary code, but this has not been confirmed.
Linksys WAP4400N devices running firmware 1.2.14 are vulnerable.
NOTE: Since the flaw is in the Marvell 88W8361P-BEM1 chipset driver, other devices and firmware versions using the same code may also be affected.
Exploit / POC
Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Linksys WAP4400N Marvell Wireless Chipset Driver Remote Denial of Service Vulnerability
References:
References:
- Marvell Homepage (Marvell Semiconductor)
- WAP4400N Product Page (Linksys)
- Marvell Driver Malformed Association Request Vulnerability (Laurent Butti
)