CVE-2009-0282: Integer Overflow

Published Jan 27, 2009
·
Updated

Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.

Affected Software

4 affected components
Ralinktech Rt73=3.08
Microsoft Windows 2000
All of the following
Ralinktech Rt73=3.08
Microsoft Windows 2000

Event History

Jan 27, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker needs to be able to send a crafted IEEE 802.11 Probe Request packet containing an overly long SSID to a vulnerable wireless adapter or driver. No authentication is required.

2

Which drivers are identified as potentially affected?

The issue is identified in the Ralink RT73 3.08 driver for Windows and is also reported to affect drivers including rt2400, rt2500, rt2570, and rt61. The provided information does not identify affected operating system versions for those other drivers.

3

What is the potential impact beyond a wireless connection failure?

A crafted packet can crash the affected driver or system, causing denial of service. The issue may also permit arbitrary code execution, with compromise of confidentiality, integrity, and availability indicated by the severity vector.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203