The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system hang) via a crafted length field in nested 802.3 Ethernet frames in Fast Frame packets, which results in a NULL pointer dereference.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Madwifi | Madwifi | * | 0.9.3 (including) |
Madwifi | Madwifi | 0.9.0 (including) | 0.9.0 (including) |
Madwifi | Madwifi | 0.9.1 (including) | 0.9.1 (including) |
Madwifi | Madwifi | 0.9.2 (including) | 0.9.2 (including) |
Madwifi | Madwifi | 0.9.2.1 (including) | 0.9.2.1 (including) |
Linux-restricted-modules-2.6.15 | Ubuntu | dapper | * |
Linux-restricted-modules-2.6.17 | Ubuntu | edgy | * |
Linux-restricted-modules-2.6.20 | Ubuntu | feisty | * |