Summary
The remote host is missing an update to ndiswrapper announced via advisory DSA 1731-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201731-1
Insight
Anders Kaseorg discovered that ndiswrapper suffers from buffer overflows via specially crafted wireless network traffic, due to incorrectly handling long ESSIDs. This could lead to the execution of arbitrary code.
For the oldstable distribution (etch), this problem has been fixed in version 1.28-1+etch1.
For the stable distribution (lenny), this problem has been fixed in version 1.53-2, which was already included in the lenny release.
For the testing distribution (squeeze) and the unstable distribution (sid), this problem has been fixed in version 1.53-2.
Severity
Classification
-
CVE CVE-2008-4395 -
CVSS Base Score: 8.3
AV:A/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities