Menu

Database

Broadcom Wireless Driver Probe Response SSID Overflow

WVE ID: WVE-2006-0071

Type: Vulnerability

Status: Candidate

Classification:
Hijacking
Input Manipulation
Design Flaw

Description:
The Broadcom BCMWL5.SYS wireless device driver is vulnerable to a stack-based buffer overflow that can lead to arbitrary kernel-mode code execution. This particular vulnerability is caused by improper handling of 802.11 probe responses containing a long SSID field.

Discussion:
This vulnerability only applies to the Windows platform or to Linux and BSD systems using ndiswrapper with the Windows driver. The BCMWL5.SYS driver is bundled with new PCs from HP, Dell, Gateway, eMachines, and other computer manufacturers. Version 3.50.21.10 of the driver is known to be vulnerable and it is likely that other versions are vulnerable as well. Broadcom has released a fixed driver to their partners, which are in turn providing updates for the affected products. Linksys, Zonet, and other wireless card manufactures also provide devices that ship with this driver.


An exploit for the vulnerability has been added to the Metasploit framework. The vulnerability does not require that the client be associated with an AP, simply that it is in range of the PC running the exploit. Because it allows remote code execution in the kernel it potentially allows an attacker to completely take over the target PC.

Credits
Author: Johnny Cache (johnnycsh@802.11mercenary.com) : None
Author: Chris Eagle : None

References
URL: http://projects.info-pull.com/mokb/MOKB-11-11-2006.html
URL: http://isotf.org/advisories/zert-01-111106.htm

Released: 2006-11-11

Submitter
Chris Waters (cwaters@networkchemistry.com) : Network Chemistry

Submitted: Mon Nov 13 15:27:12 -0800 2006

Candidate Date: Mon Nov 13 15:29:19 -0800 2006


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...