Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2010-4648

Overview

Vulnerability Score 3.3 3.3
CVE Id CVE-2010-4648
Last Modified 26 Jun 2012 12:00:00
Published 21 Jun 2012 07:55:01
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector ADJACENT_NETWORK
Access Complexity LOW
Authentication NONE

CVE-2010-4648

Summary

The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

Vulnerable Systems

Operating System

  • Linux Kernel 2.6.36.1

  • Linux Kernel 2.6.36.2

  • Linux Kernel 2.6.36.3

  • Linux Kernel 2.6.36.4


References

CONFIRM - https://github.com/torvalds/linux/commit/0a54917c3fc295cb61f3fb52373c173fd3b69f48

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=667907

MLIST - [oss-security] 20110106 Re: CVE Request: kernel [Re: Security review of 2.6.32.28]

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0a54917c3fc295cb61f3fb52373c173fd3b69f48

CONFIRM - http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37


Last Updated: 27 May 2016 10:56:34