blob: c6988d0b9f3219cbb3a7f760a90520cf46b74c48 [file] [log] [blame]
<?xml version="1.0" encoding="utf-8"?>
<glsa id="200907-08">
<title>Multiple Ralink wireless drivers: Execution of arbitrary code</title>
An integer overflow in multiple Ralink wireless drivers might lead to the
execution of arbitrary code with elevated privileges.
<product type="ebuild">rt2400 rt2500 rt2570 rt61 ralink-rt61</product>
<announced>July 12, 2009</announced>
<revised>July 12, 2009: 01</revised>
<package name="net-wireless/rt2400" auto="yes" arch="*">
<vulnerable range="le">1.2.2_beta3</vulnerable>
<package name="net-wireless/rt2500" auto="yes" arch="*">
<vulnerable range="le">1.1.0_pre2007071515</vulnerable>
<package name="net-wireless/rt2570" auto="yes" arch="*">
<vulnerable range="le">20070209</vulnerable>
<package name="net-wireless/rt61" auto="yes" arch="*">
<vulnerable range="le">1.1.0_beta2</vulnerable>
<package name="net-wireless/ralink-rt61" auto="yes" arch="*">
<vulnerable range="le"></vulnerable>
All listed packages are external kernel modules that provide drivers
for multiple Ralink devices. ralink-rt61 is released by,
the other packages by the project.
Aviv reported an integer overflow in multiple Ralink wireless card
drivers when processing a probe request packet with a long SSID,
possibly related to an integer signedness error.
<impact type="high">
A physically proximate attacker could send specially crafted packets to
a user who has wireless networking enabled, possibly resulting in the
execution of arbitrary code with root privileges.
Unload the kernel modules.
All external kernel modules have been masked and we recommend that
users unmerge those drivers. The Linux mainline kernel has equivalent
support for these devices and the vulnerability has been resolved in
stable versions of sys-kernel/gentoo-sources.
# emerge --unmerge &quot;net-wireless/rt2400&quot;
# emerge --unmerge &quot;net-wireless/rt2500&quot;
# emerge --unmerge &quot;net-wireless/rt2570&quot;
# emerge --unmerge &quot;net-wireless/rt61&quot;
# emerge --unmerge &quot;net-wireless/ralink-rt61&quot;</code>
<uri link="">CVE-2009-0282</uri>
<metadata tag="requester" timestamp="Thu, 09 Jul 2009 18:18:38 +0000">
<metadata tag="submitter" timestamp="Thu, 09 Jul 2009 18:30:24 +0000">
<metadata tag="bugReady" timestamp="Sun, 12 Jul 2009 15:41:07 +0000">