CVE-2014-8322: Buffer Overflow
Published Jan 31, 2020
·Updated
Stack-based buffer overflow in the tcptest function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
Affected Software
4 affected components
aircrack-ng Aircrack-ng<=1.1
aircrack-ng Aircrack-ng=1.2-beta1
aircrack-ng Aircrack-ng=1.2-beta2
aircrack-ng Aircrack-ng=1.2-beta3
Remediation
Patch Available
Event History
Jan 31, 2020
CVE Published
via MITRE·09:21 PM
Data Sourced
via MITRE·09:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8322?
CVE-2014-8322 has been rated as high severity due to the potential for remote code execution.
2
How do I fix CVE-2014-8322?
To fix CVE-2014-8322, upgrade Aircrack-ng to version 1.2 RC 1 or later.
3
What causes the vulnerability in CVE-2014-8322?
CVE-2014-8322 is caused by a stack-based buffer overflow in the tcp_test function.
4
Which versions of Aircrack-ng are affected by CVE-2014-8322?
Aircrack-ng versions prior to 1.2 RC 1, including 1.1 and the 1.2 beta versions, are affected by CVE-2014-8322.
5
Can CVE-2014-8322 be exploited remotely?
Yes, CVE-2014-8322 can be exploited remotely via a crafted length parameter value.