CVE-2009-0282: Integer Overflow
Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to be able to send a crafted IEEE 802.11 Probe Request packet containing an overly long SSID to a vulnerable wireless adapter or driver. No authentication is required.
Which drivers are identified as potentially affected?
The issue is identified in the Ralink RT73 3.08 driver for Windows and is also reported to affect drivers including rt2400, rt2500, rt2570, and rt61. The provided information does not identify affected operating system versions for those other drivers.
What is the potential impact beyond a wireless connection failure?
A crafted packet can crash the affected driver or system, causing denial of service. The issue may also permit arbitrary code execution, with compromise of confidentiality, integrity, and availability indicated by the severity vector.