CVE-2006-0226: Integer Overflow
Published Jan 19, 2006
·Updated
Integer overflow in IEEE 802.11 network subsystem (ieee80211ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.
Affected Software
2 affected components
FreeBSD FreeBSD=6.0-release
FreeBSD FreeBSD=6.0-stable
Remediation
Patch Available
Patch Available
Event History
Jan 19, 2006
CVE Published
01:03 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0226?
CVE-2006-0226 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2006-0226?
To fix CVE-2006-0226, upgrade to a version of FreeBSD that is 6.0-STABLE or later.
3
What type of attack does CVE-2006-0226 allow?
CVE-2006-0226 allows remote attackers to execute arbitrary code through crafted wireless network frames.
4
Which versions of FreeBSD are affected by CVE-2006-0226?
CVE-2006-0226 affects FreeBSD versions prior to 6.0-STABLE including 6.0-RELEASE.
5
What component is involved in CVE-2006-0226?
CVE-2006-0226 involves the IEEE 802.11 network subsystem in FreeBSD.