WVE ID: WVE-2008-0008
Type: Vulnerability
Status: Candidate
Classification:
Input Manipulation
Description:
Some Atheros drivers used in access points such as the Linksys WRT350N do not correctly parse the Atheros vendor-specific IE tags.
Discussion:
A malicious association request sent to the AP with an Atheros IE with an inappropriate length (too long) can cause a denial of service and potentially lead to code execution. The association request must be sent after a successful 802.11 authentication exchange.
Credits
References
URL:
http://www.securityfocus.com/archive/1/495984/30/0/threaded
Released: 2008-09-04
Submitter
: None
Submitted: Mon Sep 15 07:06:24 -0700 2008
Candidate Date: Wed Sep 17 12:27:41 -0700 2008

