Menu

Database

Apple Airport Driver Remote Code Execution Vulnerability

WVE ID: WVE-2006-0067

Type: Vulnerability

Status: Candidate

Classification:
Input Manipulation

Description:
The driver for Apple's Airport wireless card that utilizes an ORiNOCO chipset is vulnerable to memory corruption which can lead to execution of arbitrary code.

Discussion:
Apple's Airport products prior to the introduction of their Airport Extreme product line utilized the ORiNOCO 802.11b chipset. A vulnerability exists in the driver for these devices which can allow a remote attacker to corrupt kernel memory and execute arbitrary code on the affected system.

The vulnerability stems from improper handling of malformed probe response frames. Thus an attacker can send such a frame with a malicious payload and cause it to be executed.

Currently there is no patch for this issue. An exploit for it has been included in the 3.x series of Metasploit.

Credits
Author: H D Moore : Metasploit Project

References
BID: http://www.securityfocus.com/bid/20862
FULLDISC: http://seclists.org/fulldisclosure/2006/Nov/0008.html
URL: http://projects.info-pull.com/mokb/MOKB-01-11-2006.html
WVE: WVE-2006-0068

Released: 2006-11-01

Submitter
Andrew Lockhart (alockhart@networkchemistry.com) : Network Chemistry

Submitted: Fri Nov 03 10:37:02 -0800 2006

Candidate Date: Fri Nov 03 10:37:57 -0800 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...