CVE-2014-8323: Input Validation
Published Oct 17, 2017
·Updated
buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.
Affected Software
1 affected component
aircrack-ng Aircrack-ng<=1.2
Remediation
Patch Available
Event History
Oct 17, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8323?
CVE-2014-8323 has a severity rating that indicates it can lead to a denial of service through a segmentation fault.
2
How do I fix CVE-2014-8323?
To fix CVE-2014-8323, update Aircrack-ng to version 1.2 Beta 3 or later.
3
What causes the vulnerability CVE-2014-8323?
CVE-2014-8323 is caused by a crafted length parameter in a response that leads to a segmentation fault.
4
Is CVE-2014-8323 present in all versions of Aircrack-ng?
CVE-2014-8323 is present in Aircrack-ng versions prior to 1.2 Beta 3.
5
Who is affected by CVE-2014-8323?
Remote attackers can exploit CVE-2014-8323 to affect users of vulnerable Aircrack-ng versions.