First published: Tue Sep 05 2017(Updated: )
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.
Credit: Gal Beniamini Google Project ZeroGal Beniamini Google Project ZeroGal Beniamini Google Project ZeroGal Beniamini Google Project Zero cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <11 | 11 |
Apple iOS | <11 | 11 |
Broadcom Bcm4355c0 Firmware | =9.44.78.27.0.1.56 | |
Broadcom BCM4355C0 | ||
Apple iPhone OS | <11.0 | |
Apple tvOS | <11.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-11120 is a memory corruption issue in Wi-Fi chips that can be exploited by crafting a malformed RRM neighbor report frame.
CVE-2017-11120 has a severity rating of critical (9).
Broadcom BCM4355C0 firmware version 9.44.78.27.0.1.56 is affected by CVE-2017-11120 and is vulnerable to an internal buffer overflow triggered by a malformed RRM neighbor report frame.
CVE-2017-11120 can be fixed by upgrading Apple tvOS to version 11 or higher.
You can find more information about CVE-2017-11120 on the following references: http://packetstormsecurity.com/files/144328/Broadcom-802.11k-Neighbor-Report-Response-Out-Of-Bounds-Write.html, http://www.securityfocus.com/bid/100984, and https://bugs.chromium.org/p/project-zero/issues/detail?id=1289.