Networking Forums

Networking Forums > Wireless Networking > Wireless Internet > NEWS: Broadcom flaw spawns wireless risk

Reply
Thread Tools Display Modes

NEWS: Broadcom flaw spawns wireless risk

 
 
John Navas
Guest
Posts: n/a

 
      11-16-2006, 12:35 AM
<http://www.theregister.com/2006/11/15/broadcom_driver_flaw/>

Security researchers have discovered a vulnerability
(http://www.kb.cert.org/vuls/id/209376) in Broadcom wireless
device drivers.

Flaws in handling 802.11 probe responses containing a long SSID
field mean that systems that use the Broadcom BCMWL5.SYS wireless
device driver are left open to buffer overflow attacks. The flaw
might be used by hackers within radio range to inject hostile code
into vulnerable systems. The list of potential targets (Broadcom
partners) is extensive.

The flaw does not lend itself to remote attack across the internet
but it does mean that hackers within radio range (for example when a
user is in the vicinity of a hot spot used by an attacker) might be
able be mount either a denial of service or code injection attack.
Users are advised to turn off their wireless cards when not in use
pending the availability of updates from Broadcom's partners.

The affected driver is bundled with new PCs from Dell, Gateway and
HP among other computer manufacturers. Wireless card manufactures
including Linksys also provide devices that ship with this driver.
...

[MORE]

--
Best regards, FAQ for Wireless Internet: <http://Wireless.wikia.com>
John Navas FAQ for Wi-Fi: <http://wireless.wikia.com/wiki/Wi-Fi>
Wi-Fi How To: <http://wireless.wikia.com/wiki/Wi-Fi_HowTo>
Fixes to Wi-Fi Problems: <http://wireless.wikia.com/wiki/Wi-Fi_Fixes>
 
Reply With Quote
 
 
 
 
Jeff Liebermann
Guest
Posts: n/a

 
      11-16-2006, 04:15 AM
John Navas <(E-Mail Removed)> hath wroth:

><http://www.theregister.com/2006/11/15/broadcom_driver_flaw/>
>
> Security researchers have discovered a vulnerability
> (http://www.kb.cert.org/vuls/id/209376) in Broadcom wireless
> device drivers.


Note that Linksys says it only uses the affected driver on one
product, WPC300N:
http://www.kb.cert.org/vuls/id/MAPG-6VGNHW
A fix has already been issued but doesn't list the buffer overflow
problem in the release notes. As mentioned, other drivers and
versions may be affected.


--
Jeff Liebermann (E-Mail Removed)
150 Felker St #D http://www.LearnByDestroying.com
Santa Cruz CA 95060 http://802.11junk.com
Skype: JeffLiebermann AE6KS 831-336-2558
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
NEWS: 'Hospital risk' from radio tags John Navas Wireless Internet 1 06-26-2008 03:01 AM
NEWS: WIFI - Children at risk from 'electronic smog' aljuhani Wireless Internet 26 05-04-2007 09:41 PM
Flaw in SMB not fixed after SP. =?Utf-8?B?TmVyc2Vz?= Windows Networking 0 03-21-2005 09:15 PM
Wireless Devices - Security Risk? b1377@worldnet.att.net Wireless Internet 9 06-10-2004 03:24 AM
Is wireless broadband a security risk? Mickle Wireless Internet 5 02-17-2004 12:31 AM



1 2 3 4 5 6 7 8 9 10 11