First published: Fri Jan 31 2020(Updated: )
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aircrack-ng | <=1.1 | |
Aircrack-ng | =1.2-beta1 | |
Aircrack-ng | =1.2-beta2 | |
Aircrack-ng | =1.2-beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8322 has been rated as high severity due to the potential for remote code execution.
To fix CVE-2014-8322, upgrade Aircrack-ng to version 1.2 RC 1 or later.
CVE-2014-8322 is caused by a stack-based buffer overflow in the tcp_test function.
Aircrack-ng versions prior to 1.2 RC 1, including 1.1 and the 1.2 beta versions, are affected by CVE-2014-8322.
Yes, CVE-2014-8322 can be exploited remotely via a crafted length parameter value.