KisMAC 802.11 Cisco vendor tag WavePacket:parseTaggedData() parsing buffer overflow

kismac-80211-parsing-bo (25422) The risk level is classified as HighHigh Risk

Description:

KisMAC is vulnerable to a buffer overflow, caused by improper checking in the WavePacket:parseTaggedData() function when parsing the Cisco vendor tag for additional SSIDs in a received 802.11 management frame. A remote attacker could exploit this vulnerability to execute arbitrary code on the system.


Consequences:

Gain Access

Remedy:

Upgrade to the latest version of KisMAC (R73p or later), available from the KisMAC Web page. See References.

References:

  • Full-Disclosure Mailing List, Thu Mar 23 2006 - 01:33:25 CST: Advisory 03/2006: KisMAC Cisco Vendor Tag Encapsulated SSID Overflow.
  • KisMAC Web site: freshmeat.net: Project details for KisMAC.
  • BID-17198: KisMAC Cisco Vendor Tag Remote Buffer Overflow Vulnerability
  • CVE-2006-1385: Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.
  • OSVDB ID: 24072: KisMAC 80211 Management Frame Cisco Vendor Tag SSID Value Overflow
  • SA19354: KisMAC Cisco Vendor Tag SSID Parsing Buffer Overflow
  • VUPEN/ADV-2006-1070: KisMAC Cisco Vendor Tag Encapsulated SSID Remote Buffer Overflow Vulnerability

Platforms Affected:

  • KisMAC KisMAC prior to R73p

Reported:

Mar 23, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page