Vulnerabilities > CVE-2006-0226 - Unspecified vulnerability in Freebsd 6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 2 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 16296 CVE(CAN) ID: CVE-2006-0226 FreeBSD的IEEE 802.11网络子系统可为无线联网实现协议协商。 FreeBSD的IEEE 802.11在处理协议协商时存在漏洞,远程攻击者可能利用此漏洞在主机上执行任意指令。 在扫描已有的无线网络时,如果处理了被破坏的IEEE 802.11信标或探测响应帧的话就会出现整数溢出,导致帧溢出缓冲区。能够广播特制信标或探测响应帧的攻击者可以在任何扫描无线网络的系统上以FreeBSD Kernel权限执行任意代码。 FreeBSD FreeBSD 6.0-STABLE FreeBSD FreeBSD 6.0-RELEASE FreeBSD ------- FreeBSD已经为此发布了一个安全公告(FreeBSD-SA-06:05)以及相应补丁: FreeBSD-SA-06:05:IEEE 802.11 buffer overflow 链接:<a href=ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc target=_blank>ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc</a> 补丁下载: * FreeBSD 80211.patch <a href=ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-06:05/80211.patch target=_blank>ftp://ftp.freebsd.org/pub/FreeBSD/CERT/patches/SA-06:05/80211.patch</a> |
id | SSV:4223 |
last seen | 2017-11-19 |
modified | 2006-08-17 |
published | 2006-08-17 |
reporter | Root |
title | FreeBSD IEEE 802.11网络子系统远程溢出漏洞 |
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:05.80211.asc
- http://kernelwars.blogspot.com/2007/01/alive.html
- http://kernelwars.blogspot.com/2007/01/alive.html
- http://secunia.com/advisories/18353
- http://secunia.com/advisories/18353
- http://securitytracker.com/id?1015518
- http://securitytracker.com/id?1015518
- http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson
- http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Eriksson
- http://www.osvdb.org/22537
- http://www.osvdb.org/22537
- http://www.securityfocus.com/bid/16296
- http://www.securityfocus.com/bid/16296
- http://www.signedness.org/advisories/sps-0x1.txt
- http://www.signedness.org/advisories/sps-0x1.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24192