REDHAT-BUG-1159812: Medium severity aircrack-ng Aircrack-ng vulnerability
It was reported [1] that four vulnerabilities exist on aircrack-ng <= 1.2 Beta 3 which allow remote/local code execution, privilege escalation and denial of service. Specifically, the following vulnerabilities were identified: - CVE-2014-8321 A stack overflow at airodump-ng gpstracker() which may lead to code execution, privilege escalation. https://github.com/aircrack-ng/aircrack-ng/commit/ff70494dd389ba570dbdbf36f217c28d4381c6b5 - CVE-2014-8322 A length parameter inconsistency at aireplay tcptest() which may lead to remote code execution. https://github.com/aircrack-ng/aircrack-ng/commit/091b153f294b9b695b0b2831e65936438b550d7b - CVE-2014-8323 A missing check for data format at buddy-ng which may lead to denial of service. https://github.com/aircrack-ng/aircrack-ng/commit/da087238963c1239fdabd47dc1b65279605aca70 - CVE-2014-8324 A missing check for invalid values at airserv-ng netget() which may lead to denial of service. https://github.com/aircrack-ng/aircrack-ng/commit/88702a3ce4c28a973bf69023cd0312f412f6193e
Soon a new version will be released but at the time there is no patched version.
[1]: http://seclists.org/bugtraq/2014/Nov/1
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1159812?
The severity of REDHAT-BUG-1159812 is high due to the potential risks of remote code execution and privilege escalation.
How do I fix REDHAT-BUG-1159812?
To fix REDHAT-BUG-1159812, upgrade aircrack-ng to a version greater than 1.2 Beta 3.
What vulnerabilities are addressed in REDHAT-BUG-1159812?
REDHAT-BUG-1159812 addresses four vulnerabilities that can lead to remote code execution, privilege escalation, and denial of service.
Which versions of aircrack-ng are affected by REDHAT-BUG-1159812?
Aircrack-ng versions up to and including 1.2 Beta 3 are affected by REDHAT-BUG-1159812.
What actions should be taken if REDHAT-BUG-1159812 is exploited?
If REDHAT-BUG-1159812 is exploited, it is crucial to immediately apply the necessary updates and monitor systems for unusual activity.