CVE-2007-6025: Buffer Overflow
Description of problem:
Kees Cook reported this to the Debian BTS: There is a stack overflow in wpasupplicant when handling TSF info from drivers that support it. Patch attached.
Other sources
Stack-based buffer overflow in driverwext.c in wpasupplicant 0.6.0 and earlier allows remote attackers to cause a denial of service (crash) via crafted TSF data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6025?
CVE-2007-6025 is classified as a high severity vulnerability due to its potential to allow remote attackers to cause a stack overflow.
How do I fix CVE-2007-6025?
To fix CVE-2007-6025, users should upgrade to wpa_supplicant version 0.6.1 or later.
What systems are affected by CVE-2007-6025?
CVE-2007-6025 affects wpa_supplicant versions 0.6.0 and earlier.
What types of attacks can exploit CVE-2007-6025?
CVE-2007-6025 can be exploited by remote attackers causing a stack-based buffer overflow.
Is there a known exploit for CVE-2007-6025?
Yes, exploits for CVE-2007-6025 may be published, but the details can vary.