Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-4395

Overview

Vulnerability Score 8.3 8.3
CVE Id CVE-2008-4395
Last Modified 29 Oct 2012 11:17:17
Published 06 Nov 2008 10:55:51
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector ADJACENT_NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-4395

Summary

Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.

Vulnerable Systems

Operating System

  • Linux Kernel 2.6

  • Ubuntu Linux Kernel 2.6.26


References

CONFIRM - https://bugs.launchpad.net/ubuntu/+source/linux/+bug/275860

CONFIRM - https://bugs.launchpad.net/bugs/cve/2008-4395

XF - linux-kernel-ndiswrapper-bo(46437)

UBUNTU - USN-662-1

MLIST - [frugalware-git] 20081014 kernel2627: ndiswrapper-1.53-6-i686

SECUNIA - 32509

SUSE - SUSE-SA:2008:057

CONFIRM - http://git.frugalware.org/gitweb/gitweb.cgi?p=frugalware-current.git;a=commitdiff;h=49945b423c2f7e33b4c579ca460df6a806ee8f9f

CONFIRM - http://bugs.gentoo.org/show_bug.cgi?id=239371

UBUNTU - USN-662-2

SECTRACK - 1021142

BID - 32118


Last Updated: 27 May 2016 10:49:34